CVE-2019-11252: Credential leakage when failing to mount
The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-11252?
CVE-2019-11252 is a vulnerability in the Kubernetes kube-controller-manager that allows credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.
How severe is CVE-2019-11252?
CVE-2019-11252 has a severity rating of 6.5, which is considered medium.
Which versions of Kubernetes are affected by CVE-2019-11252?
The Kubernetes kube-controller-manager versions v1.0-v1.17 are affected by CVE-2019-11252.
How can I fix the CVE-2019-11252 vulnerability?
To fix the CVE-2019-11252 vulnerability, you should update Kubernetes to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2019-11252?
You can find more information about CVE-2019-11252 on the GitHub page at: https://github.com/kubernetes/kubernetes/pull/88684