Kubernetes client-go logs authorization headers at debug verbosity levels
Published Aug 29, 2019
6.5
MEDIUMCVSS 3.1
EPSS 1.77%
Description
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
Affected products
-
- Version prior to 1.16StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Kubernetes | n/a |
|
Configuration 1
- < 1.15.3
- 1.15.3
- 1.15.4
- 1.16.0
- 1.16.0
- 1.16.0
- 1.16.0
- 1.16.0
Configuration 2
- 3.11
- 4.1
No data.
Red Hat OpenShift Container Platform 3.11
atomic-openshift-0:3.11.157-1.git.0.dfe38da.el7
Fixed · RHSA-2019:4052
Red Hat OpenShift Container Platform 4.1
openshift-0:4.1.27-201912021146.git.0.a40116f.el8_0
Fixed · RHSA-2019:4087
Red Hat Edge Manager preview
flightctl
Not affected
Red Hat OpenShift Container Platform 3.10
atomic-openshift
Affected
Red Hat OpenShift Container Platform 3.9
atomic-openshift
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-0:3.11.157-1.git.0.dfe38da.el7 | Fixed | RHSA-2019:4052 |
| Red Hat OpenShift Container Platform 4.1 | openshift-0:4.1.27-201912021146.git.0.a40116f.el8_0 | Fixed | RHSA-2019:4087 |
| Red Hat Edge Manager preview | flightctl | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Affected | n/a |
k8s.io/client-go
Go
Introduced 0 Fixed 0.17.0k8s.io/kubernetes
Go
Introduced 0 Fixed 1.16.0-beta.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | k8s.io/client-go | 0 | 0.17.0 |
| Go | k8s.io/kubernetes | 0 | 1.16.0-beta.1 |
Remediation
Vendor solution
lower log verbosity levels to <= 6
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
AV:N/AC:M/Au:S/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.77% (0.01766) | 77.30th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.77% (0.01766) | 75.11th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.98% (0.00976) | 74.67th | v4 (v2025.03.14) |
| Mar 29, 2025 | 7.08% (0.07080) | 85.53th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.85% (0.00854) | 73.34th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.17% (0.00169) | 55.21th | v3 (v2023.03.01) |
| Jun 26, 2024 | 0.11% (0.00112) | 44.84th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.11% (0.00112) | 42.82th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00950) | 28.61th | v2 (v2022.01.01) |
| Feb 4, 2022 | 14.47% (0.14469) | 91.13th | v2 (v2022.01.01) |
| Feb 3, 2022 | 5.36% (0.05363) | 79.74th | v1 |
| Jan 6, 2022 | 5.36% (0.05363) | 79.54th | v1 |
| Jan 5, 2022 | 1.25% (0.01247) | 69.74th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.25% (0.01247) | 0.00th | v1 |
References (13)
- http://www.openwall.com/lists/oss-security/2020/10/16/2 mailing-listx_refsource_MLIST
- https://access.redhat.com/errata/RHSA-2019:4052 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4087 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11250 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1740434 Issue Tracking
- https://github.com/advisories/GHSA-jmrx-5g74-6v2f Advisory
- https://github.com/kubernetes/kubernetes/commit/4441f1d9c3e94d9a3d93b4f184a591cab02a5245
- https://github.com/kubernetes/kubernetes/issues/81114 x_refsource_CONFIRMThird Party Advisory
- https://github.com/kubernetes/kubernetes/pull/81330
- https://nvd.nist.gov/vuln/detail/CVE-2019-11250
- https://pkg.go.dev/vuln/GO-2021-0065
- https://security.netapp.com/advisory/ntap-20190919-0003 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11250
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2020/10/16/2 | mailing-listx_refsource_MLIST | |
| https://access.redhat.com/errata/RHSA-2019:4052 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2019:4087 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-11250 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1740434 | Issue Tracking | |
| https://github.com/advisories/GHSA-jmrx-5g74-6v2f | Advisory | |
| https://github.com/kubernetes/kubernetes/commit/4441f1d9c3e94d9a3d93b4f184a591cab02a5245 | ||
| https://github.com/kubernetes/kubernetes/issues/81114 | x_refsource_CONFIRMThird Party Advisory | |
| https://github.com/kubernetes/kubernetes/pull/81330 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2019-11250 | ||
| https://pkg.go.dev/vuln/GO-2021-0065 | ||
| https://security.netapp.com/advisory/ntap-20190919-0003 | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-11250 |
Change history (0)
No recorded changes yet.