Advisory Published
Updated

REDHAT-BUG-1734615

First published: Wed Jul 31 2019(Updated: )

OpenShift Container Platform 4 does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user. Upstream Fix: <a href="https://github.com/openshift/library-go/pull/472">https://github.com/openshift/library-go/pull/472</a>

Affected SoftwareAffected VersionHow to fix
Red Hat OpenShift Container Platform for IBM LinuxONE

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of REDHAT-BUG-1734615?

    The severity of REDHAT-BUG-1734615 is considered moderate due to the potential exposure of sensitive data in pod logs.

  • How do I fix REDHAT-BUG-1734615?

    To fix REDHAT-BUG-1734615, ensure that the log level in your operators is set below Debug to prevent sensitive data from being written to logs.

  • Who is affected by REDHAT-BUG-1734615?

    Users of Red Hat OpenShift Container Platform 4 who allow debug logging in their operators are affected by REDHAT-BUG-1734615.

  • What are the implications of REDHAT-BUG-1734615?

    The implications of REDHAT-BUG-1734615 include the risk of low privileged users gaining access to sensitive secret data through pod logs.

  • Is there a workaround for REDHAT-BUG-1734615?

    Yes, a temporary workaround for REDHAT-BUG-1734615 is to restrict the log level configuration to below Debug in your OpenShift operators.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203