Back

MEDIUM

Kubernetes client-go logs authorization headers at debug verbosity levels

Published Aug 29, 2019

Description

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

Affected products

Remediation

Vendor solution

lower log verbosity levels to <= 6

Metrics

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Aug 29, 2019
Updated Sep 17, 2024
Reserved Apr 17, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 13, 2019
GHSA-JMRX-5G74-6V2F