Back

HIGH

kubernetes: Authentication information exposure in rest.AnonymousClientConfig()

Published Apr 22, 2019

Description

In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not effectively clear service account credentials loaded using rest.InClusterConfig()

Affected products

Remediation

Vendor solution

Clear the config.WrapTransport and config.Transport fields in addition to calling rest.AnonymousClientConfig()

Red Hat statement

This issue does not affect the version of Kubernetes(embedded in heketi) shipped with Red Hat Gluster Storage 3 as it does not contain the vulnerable functionality.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Apr 22, 2019
Updated Aug 4, 2024
Reserved Apr 17, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 22, 2019
GHSA-GC2P-G4FG-29VH