openshift/installer: kubeconfig and kubeadmin-password are created with word-readable permissions
Published Mar 18, 2020
4.4
MEDIUMCVSS 3.1
EPSS 0.33%
Description
During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials used to authenticate to the OpenShift API server, and are incorrectly assigned word-readable permissions. ose-installer as shipped in Openshift 4.2 is vulnerable.
Affected products
-
- Version ose-installer as shipped in Openshift 4.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Red Hat | Openshift/installer | n/a |
|
No data.
Red Hat OpenShift Container Platform 4.2
openshift4/ose-baremetal-installer-rhel7:v4.2.18-202002031246
Fixed · RHSA-2020:0476
Red Hat OpenShift Container Platform 4.2
openshift4/ose-cli-artifacts:v4.2.18-202002031246
Fixed · RHSA-2020:0476
Red Hat OpenShift Container Platform 4.2
openshift4/ose-installer:v4.2.18-202002031246
Fixed · RHSA-2020:0463
Red Hat OpenShift Container Platform 4
openshift4/ose-installer-artifacts
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4.2 | openshift4/ose-baremetal-installer-rhel7:v4.2.18-202002031246 | Fixed | RHSA-2020:0476 |
| Red Hat OpenShift Container Platform 4.2 | openshift4/ose-cli-artifacts:v4.2.18-202002031246 | Fixed | RHSA-2020:0476 |
| Red Hat OpenShift Container Platform 4.2 | openshift4/ose-installer:v4.2.18-202002031246 | Fixed | RHSA-2020:0463 |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-installer-artifacts | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2019-19335 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1777209 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19335 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8956 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-19335
- https://www.cve.org/CVERecord?id=CVE-2019-19335
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-19335 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1777209 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19335 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8956 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-19335 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-19335 |
Change history (0)
No recorded changes yet.