Lucene search

K
osvGoogleOSV:GHSA-JMRX-5G74-6V2F
HistoryMay 24, 2022 - 4:55 p.m.

Kubernetes client-go library logs may disclose credentials to unauthorized users

2022-05-2416:55:06
Google
osv.dev
12
kubernetes
client-go
library
credentials
unauthorized users
logs
request headers
verbosity levels
disclosure
command output
kube-apiserver
v1.16.0
basic token authentication
bearer token authentication
high verbosity levels
affected

EPSS

0.002

Percentile

53.9%

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.