CVE-2019-10223
published 2019-11-05CVE-2019-10223: A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.78%
75.9th percentile
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl` behavior and this new feature can cause the entire secret content to end up in metric labels thus inadvertently exposing the secret content in metrics. This feature has been reverted and released as the v1.7.2 release. If you are running the v1.7.0 or v1.7.1 release, please upgrade to the v1.7.2 release as soon as possible.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | kubernetes_kube-state-metrics | >= 1.7.0 < 1.7.2 | 1.7.2 |
| k8s.io | kube-state-metrics | >= 1.7.0 < 1.7.2 | 1.7.2 |
| kubernetes | kube-state-metrics | — | — |
| kubernetes | kube-state-metrics | — | — |
| red_hat | kube-state-metrics | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
kube-state-metrics may expose secret content in metrics
osv·2022-05-24
CVE-2019-10223 [MEDIUM] kube-state-metrics may expose secret content in metrics
kube-state-metrics may expose secret content in metrics
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl` behavior and this new feature can cause the entire secret content to end up in metric labels thus inadvertently exposing the secret content in metrics. This feature has been reverted and released as the v1.7.2 release. If you are running the v1.7.0 or v1.7.1 release, please upgrade to the v1.7.2 release as soon as possible.
GHSA
kube-state-metrics may expose secret content in metrics
ghsa·2022-05-24
CVE-2019-10223 [MEDIUM] CWE-200 kube-state-metrics may expose secret content in metrics
kube-state-metrics may expose secret content in metrics
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl` behavior and this new feature can cause the entire secret content to end up in metric labels thus inadvertently exposing the secret content in metrics. This feature has been reverted and released as the v1.7.2 release. If you are running the v1.7.0 or v1.7.1 release, please upgrade to the v1.7.2 release as soon as possible.
OSV
Exposure of sensitive information in k8s.io/kube-state-metrics
osv·2021-05-18
CVE-2019-10223 Exposure of sensitive information in k8s.io/kube-state-metrics
Exposure of sensitive information in k8s.io/kube-state-metrics
Exposing annotations as metrics can leak secrets.
An experimental feature of kube-state-metrics enables annotations to be exposed as metrics. By default, metrics only expose metadata about secrets. However, a combination of the default kubectl behavior and this new feature can cause the entire secret content to end up in metric labels.
OSV
Duplicate Advisory: k8s.io/kube-state-metrics Exposure of Sensitive Information
osv·2021-05-18
CVE-2019-10223 [MEDIUM] Duplicate Advisory: k8s.io/kube-state-metrics Exposure of Sensitive Information
Duplicate Advisory: k8s.io/kube-state-metrics Exposure of Sensitive Information
# Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-c92w-72c5-9x59. This link is maintained to preserve external references.
# Original Description
A security issue was discovered in kube-state-metrics 1.7.x before 1.7.2. An experimental feature was added to v1.7.0 and v1.7.1 that enabled annotations to be exposed as metrics. By default, kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default kubectl behavior and this new feature can cause the entire secret content to end up in metric labels, thus inadvertently exposing the secret content in metrics.
Red Hat
kube-state-metrics: annotations exposed as metrics in combination with `kubectl` can allow for exposure of secrets
vendor_redhat·2019-08-09·CVSS 6.5
CVE-2019-10223 [MEDIUM] CWE-200 kube-state-metrics: annotations exposed as metrics in combination with `kubectl` can allow for exposure of secrets
kube-state-metrics: annotations exposed as metrics in combination with `kubectl` can allow for exposure of secrets
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl` behavior and this new feature can cause the entire secret content to end up in metric labels thus inadvertently exposing the secret content in metrics. This feature has been reverted and released as the v1.7.2 release. If you are running the v1.7.0 or v1.7.1 release, please upgrade to the v1.7.2 release as soon as possible.
Package: openshift3/ose-kube-state-me
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2019/08/15/8https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10223https://github.com/kubernetes/kube-state-metrics/releases/tag/v1.7.2https://www.openwall.com/lists/oss-security/2019/08/09/1http://www.openwall.com/lists/oss-security/2019/08/15/8https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10223https://github.com/kubernetes/kube-state-metrics/releases/tag/v1.7.2https://www.openwall.com/lists/oss-security/2019/08/09/1
2019-11-05
Published