Back

HIGH

dashboard: Authentication bypass resulting in information exposure

Published Jan 3, 2019

Description

Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of heketi shipped with 'Red Hat Gluster Storage 3' as it does not ship kubernetes dashboard.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 3, 2019
Updated Aug 5, 2024
Reserved Oct 12, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 11, 2018