First published: Wed Mar 04 2020(Updated: )
The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.
Credit: jordan@liggitt.net
Affected Software | Affected Version | How to fix |
---|---|---|
Kubernetes Kubernetes | >=1.0.0<=1.17.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11252 is a vulnerability in the Kubernetes kube-controller-manager that allows credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.
CVE-2019-11252 has a severity rating of 6.5, which is considered medium.
The Kubernetes kube-controller-manager versions v1.0-v1.17 are affected by CVE-2019-11252.
To fix the CVE-2019-11252 vulnerability, you should update Kubernetes to a version that is not affected by the vulnerability.
You can find more information about CVE-2019-11252 on the GitHub page at: https://github.com/kubernetes/kubernetes/pull/88684