cbcvebase.
CVE-2019-10165
published 2019-07-30

CVE-2019-10165: OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A…

PriorityP49low2.3CVSS 3.1
AVLACLPRHUINSUCLINAN
EPSS
0.38%
31.0th percentile
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.

Affected

2 ranges
VendorProductVersion rangeFixed in
red_hatopenshift
redhatopenshift_container_platform< 4.1.34.1.3

CVSS provenance

nvdv3.12.3LOWCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
nvdv3.02.3LOWCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.