CVE-2020-10752: High severity redhat OpenShift Container Platform vulnerability
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked OAuthToken to log into the API Server with the leaked token.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10752?
CVE-2020-10752 is classified as a moderate-severity vulnerability affecting OpenShift API Server.
How do I fix CVE-2020-10752?
To fix CVE-2020-10752, upgrade OpenShift Container Platform to a version that addresses this vulnerability.
What are the affected versions for CVE-2020-10752?
CVE-2020-10752 affects OpenShift Container Platform versions 3.11 and 4.0.
How can attackers exploit CVE-2020-10752?
Attackers can exploit CVE-2020-10752 by causing an API Server panic and then accessing the logs to retrieve leaked OAuthTokens.
What are the potential consequences of CVE-2020-10752?
The potential consequences of CVE-2020-10752 include unauthorized access to OpenShift environments due to leaked OAuthTokens.