Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-3BAECACBA93AF08FEA6013341D65BFF4
HistoryAug 29, 2019 - 12:00 a.m.

Credentials Management

2019-08-2900:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
11

EPSS

0.002

Percentile

53.9%

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.