CVE-2019-10213: Medium severity red hat openshift container platform vulnerability

Published Jul 31, 2019
·
Updated

OpenShift Container Platform 4 does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.

Upstream Fix:

https://github.com/openshift/library-go/pull/472

Other sources

OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.

MITRE

Affected Software

3 affected components
redhat OpenShift Container Platform=4.1
redhat OpenShift Container Platform=4.2
redhat Enterprise Linux=7.0

Event History

Jul 31, 2019
Data Sourced
via Red Hat·06:04 AM
DescriptionSeverityAffected Software
Nov 25, 2019
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2019-10213?

CVE-2019-10213 has been rated with moderate severity due to the exposure of sensitive secret data in pod logs.

2

How do I fix CVE-2019-10213?

To mitigate CVE-2019-10213, it is recommended to avoid setting the log level to Debug or higher in affected OpenShift Container Platform versions.

3

Which versions of OpenShift Container Platform are affected by CVE-2019-10213?

CVE-2019-10213 affects OpenShift Container Platform versions 4.1 and 4.2 specifically.

4

Can a low privileged user exploit CVE-2019-10213?

Yes, a low privileged user can access sensitive secret data by reading pod logs if the log level is set to Debug or higher.

5

Is there a workaround for CVE-2019-10213?

As a workaround for CVE-2019-10213, users should ensure that log levels remain below Debug to prevent sensitive information exposure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203