CVE-2019-11250
published 2019-08-29CVE-2019-11250: The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.77%
75.6th percentile
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kubernetes | < kubernetes 1.17.4-1 (bookworm) | kubernetes 1.17.4-1 (bookworm) |
| k8s.io | client-go | >= 0 < 0.20.0-alpha.2 | 0.20.0-alpha.2 |
| k8s.io | client-go | >= 0 < 0.17.0 | 0.17.0 |
| k8s.io | kubernetes | >= 0 < 1.16.0-beta.1 | 1.16.0-beta.1 |
| kubernetes | kubernetes | < 1.20.0-alpha2 | 1.20.0-alpha2 |
| kubernetes | kubernetes | < 1.15.3 | 1.15.3 |
| kubernetes | kubernetes | <= 1.19.3 | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| msrc | azl3_local-path-provisioner_0.0.24-5_on_azure_linux_3.0 | — | — |
| msrc | cm1_kubernetes_1.17.13-5_on_cbl_mariner_1.0 | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9
vendor_msrc·2020-12-08·CVSS 5.5
CVE-2020-8565 [MEDIUM] CWE-532 Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9
Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
kubernetes: kubernetes
Customer Action Required: Yes
Remediation: CBL-Marin
Red Hat
kubernetes: Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9
vendor_redhat·2020-10-14·CVSS 6.5
CVE-2020-8565 [MEDIUM] CWE-117 kubernetes: Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9
kubernetes: Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.
A flaw was found in kubernetes. In Kubernetes, if the logging level is to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like `kubectl`. Previously, CVE-2019-11250 was assigned for the same issue for logging levels of at least 4.
Statement: OpenShift Container Platform 4 does not support LogLevels higher than 8 (via 'TraceAll'), and is therefore
Red Hat
kubernetes: Bearer tokens written to logs at high verbosity levels (>= 7)
vendor_redhat·2019-08-13·CVSS 6.5
CVE-2019-11250 [MEDIUM] CWE-532 kubernetes: Bearer tokens written to logs at high verbosity levels (>= 7)
kubernetes: Bearer tokens written to logs at high verbosity levels (>= 7)
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
Package: flightctl (Red Hat Edge Manager preview) - Not affected
Package: atomic-openshift (Red Hat OpenShift Container Platform 3.10) - Affected
Package: atomic-openshift (Red Hat OpenShift Container Platform 3.9) - Affected
Debian
CVE-2019-11250: kubernetes - The Kubernetes client-go library logs request headers at verbosity levels of 7 o...
vendor_debian·2019·CVSS 6.5
CVE-2019-11250 [MEDIUM] CVE-2019-11250: kubernetes - The Kubernetes client-go library logs request headers at verbosity levels of 7 o...
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
Scope: local
bookworm: resolved (fixed in 1.17.4-1)
bullseye: resolved (fixed in 1.17.4-1)
forky: resolved (fixed in 1.17.4-1)
sid: resolved (fixed in 1.17.4-1)
trixie: resolved (fixed in 1.17.4-1)
OSV
Kubernetes client-go library logs may disclose credentials to unauthorized users
osv·2022-05-24
CVE-2019-11250 [MEDIUM] Kubernetes client-go library logs may disclose credentials to unauthorized users
Kubernetes client-go library logs may disclose credentials to unauthorized users
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
GHSA
Kubernetes client-go library logs may disclose credentials to unauthorized users
ghsa·2022-05-24
CVE-2019-11250 [MEDIUM] CWE-532 Kubernetes client-go library logs may disclose credentials to unauthorized users
Kubernetes client-go library logs may disclose credentials to unauthorized users
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
OSV
Unauthorized credential disclosure via debug logs in k8s.io/kubernetes and k8s.io/client-go
osv·2021-04-14·CVSS 6.5
CVE-2020-8565 [MEDIUM] Unauthorized credential disclosure via debug logs in k8s.io/kubernetes and k8s.io/client-go
Unauthorized credential disclosure via debug logs in k8s.io/kubernetes and k8s.io/client-go
Authorization tokens may be inappropriately logged if the verbosity level is set to a debug level. This is due to an incomplete fix for CVE-2019-11250.
OSV
Unauthorized credential disclosure in k8s.io/kubernetes and k8s.io/client-go
osv·2021-04-14
CVE-2019-11250 Unauthorized credential disclosure in k8s.io/kubernetes and k8s.io/client-go
Unauthorized credential disclosure in k8s.io/kubernetes and k8s.io/client-go
Authorization tokens may be inappropriately logged if the verbosity level is set to a debug level.
OSV
CVE-2019-11250: The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher
osv·2019-08-29·CVSS 6.5
CVE-2019-11250 [MEDIUM] CVE-2019-11250: The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2019-11250 remains in effect.
hackerone·2020-11-29·CVSS 6.5
CVE-2019-11250 [MEDIUM] CVE-2019-11250 remains in effect.
CVE-2019-11250 remains in effect.
Report Submission Form
## Summary:
"CVE-2019-11250: TOB-K8S-001: Bearer tokens are revealed in logs" remains in effect.
## Kubernetes Version:
Effects at least all versions since 1.4.
- This was determined with some `git` archaeology. This was determined by following the code snippet from it's current location in `kubernetes/staging/src/k8s.io/client-go/transport/round_trippers.go`
- The snippet was last meaningfully modified
- It's current location in The snippet remains relatively unchanged since
## Component Version:
I'm not sure.
## Steps To Reproduce:
1. Spin up a cluster with high verbosity: klog.V(9).Enabled()
1. Watch logs round_trippers.go `curl -k -v -X<> -H "Authorization: " `
I was having trouble getting a cluster spun up, so I have not m
Bugzilla
CVE-2020-8565 kubernetes: Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9
bugzilla·2020-10-09·CVSS 6.5
CVE-2020-8565 [MEDIUM] CVE-2020-8565 kubernetes: Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9
CVE-2020-8565 kubernetes: Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9
In Kubernetes, if the logging level is to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like `kubectl`.
Previously, CVE-2019-11250 was assigned for the same issue for logging levels of at least 4.
Discussion:
Upstream Fix:
https://github.com/kubernetes/kubernetes/pull/95316
---
Acknowledgments:
Name: the Kubernetes Product Security Committee
Upstream: Patrick Rhomberg (purelyapplied)
---
External References:
https://groups.google.com/g/kubernetes-announce/c/ScdmyORnPDk
https://github.com/kubernetes/kubernetes/issues/95623
---
This issue has been addressed in the following products:
Bugzilla
CVE-2019-11250 kubernetes: Bearer tokens written to logs at high verbosity levels (>= 7) [fedora-all]
bugzilla·2019-08-13·CVSS 6.5
CVE-2019-11250 [MEDIUM] CVE-2019-11250 kubernetes: Bearer tokens written to logs at high verbosity levels (>= 7) [fedora-all]
CVE-2019-11250 kubernetes: Bearer tokens written to logs at high verbosity levels (>= 7) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2019-11250 kubernetes: Bearer tokens written to logs at high verbosity levels (>= 7)
bugzilla·2019-08-13·CVSS 6.5
CVE-2019-11250 [MEDIUM] CVE-2019-11250 kubernetes: Bearer tokens written to logs at high verbosity levels (>= 7)
CVE-2019-11250 kubernetes: Bearer tokens written to logs at high verbosity levels (>= 7)
Kubernetes requires an authentication mechanism to enforce users’ privileges. One method of authentication, bearer tokens, are opaque strings used to associate a user with their having successfully authenticated previously. Any user with possession of this token may masquerade as the original user (the “bearer”) without further authentication.
Within Kubernetes, the bearer token is captured within the hyperkube kube-apiserver system logs at high verbosity levels (--v 10). A malicious user with access to the system logs on such a system could masquerade as any user who has previously logged into the system.
Discussion:
Created kubernetes tracking bugs for this issue:
Affects: fedora-all [bug 174043
http://www.openwall.com/lists/oss-security/2020/10/16/2https://access.redhat.com/errata/RHSA-2019:4052https://access.redhat.com/errata/RHSA-2019:4087https://github.com/kubernetes/kubernetes/issues/81114https://security.netapp.com/advisory/ntap-20190919-0003/http://www.openwall.com/lists/oss-security/2020/10/16/2https://access.redhat.com/errata/RHSA-2019:4052https://access.redhat.com/errata/RHSA-2019:4087https://github.com/kubernetes/kubernetes/issues/81114https://security.netapp.com/advisory/ntap-20190919-0003/
2019-08-29
Published