First published: Thu May 21 2020(Updated: )
When using Kafka as a storage back-end, Jaeger before 1.18.1 writes plaintext and kerberos credentials to the container log files. A low privileged user could read the logs within the pod to discover the Kafka credentials as the information is disclosed as log-level info - which is the default. References: <a href="https://github.com/jaegertracing/jaeger/releases/tag/v1.18.1">https://github.com/jaegertracing/jaeger/releases/tag/v1.18.1</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Jaeger | <1.18.1 | |
redhat/jaeger | <1.18.1 | 1.18.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.