CVE-2019-11273: PKS Telemetry logs credentials
Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user with access to those logs may be able to retrieve non-sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11273?
CVE-2019-11273 is a vulnerability found in Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7 and versions 1.4.x prior to 1.4.1.
What is the severity of CVE-2019-11273?
The severity of CVE-2019-11273 is medium, with a severity value of 4.3.
How does CVE-2019-11273 affect Pivotal Container Services?
CVE-2019-11273 affects Pivotal Container Services versions 1.3.x prior to 1.3.7 and versions 1.4.x prior to 1.4.1.
What is the impact of CVE-2019-11273?
The impact of CVE-2019-11273 is that a remote authenticated user with access to logs may be able to retrieve non-sensitive information, such as the username and password to the billing database.
How can I fix CVE-2019-11273?
To fix CVE-2019-11273, update your Pivotal Container Services installation to version 1.3.7 if using version 1.3.x, or version 1.4.1 if using version 1.4.x.