Back

MEDIUM

Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9

Published Dec 7, 2020

Description

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

Affected products

Remediation

Vendor solution

Do not enable verbose logging in production (log level >= 9), limit access to logs.

Red Hat statement

OpenShift Container Platform 4 does not support LogLevels higher than 8 (via 'TraceAll'), and is therefore not affected by this vulnerability.

Weaknesses (2)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Dec 7, 2020
Updated Sep 17, 2024
Reserved Feb 3, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 14, 2020
GHSA-8CFG-VX93-JVXW