Back

HIGH

openshift/openshift-apiserver: oauthtokens leaked to logs on panic

Published Jun 12, 2020

Description

A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked OAuthToken to log into the API Server with the leaked token.

Affected products

Remediation

Red Hat statement

OAuthTokens are only valid for 1 day by default.

Red Hat mitigation

Ensure the OpenShift API Server logs are kept private

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 12, 2020
Updated Aug 4, 2024
Reserved Mar 20, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 10, 2020