CVE-2019-10165: Low severity red hat openshift container platform vulnerability
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10165?
CVE-2019-10165 is considered a medium severity vulnerability due to the risk of exposing sensitive OAuth tokens.
How do I fix CVE-2019-10165?
To fix CVE-2019-10165, upgrade to OpenShift Container Platform version 4.1.3 or later.
What can an attacker do with the tokens exposed in CVE-2019-10165?
An attacker could recover OAuth tokens from audit logs and use them to gain unauthorized access to Kubernetes API and OpenShift resources.
Which versions of OpenShift are affected by CVE-2019-10165?
OpenShift Container Platform versions prior to 4.1.3 are affected by CVE-2019-10165.
Is there a workaround for CVE-2019-10165 until a patch is applied?
There are no specific workarounds mentioned for CVE-2019-10165, so it is recommended to upgrade as soon as possible.