Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39201
HistoryFeb 10, 2023 - 12:44 p.m.

Information Disclosure

2023-02-1012:44:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
kubernetes
vulnerability
information disclosure
round_trippers.go
authenticated connection
api server logs
client tool output
kubectl
software

0.0004 Low

EPSS

Percentile

12.7%

kubernetes is vulnerable to Information Disclosure. The vulnerability exists in the equals function of round_trippers.go which allows unauthenticated attackers to use another user’s authenticated connection to read data in the API server logs and a client tool output such as kubectl.