CVE-2020-10752
published 2020-06-12CVE-2020-10752: A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic…
PriorityP340high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
1.07%
61.1th percentile
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked OAuthToken to log into the API Server with the leaked token.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openshift | openshift_openshift-apiserver | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openshift/openshift-apiserver: oauthtokens leaked to logs on panic
vendor_redhat·2020-06-10·CVSS 7.5
CVE-2020-10752 [HIGH] CWE-522 openshift/openshift-apiserver: oauthtokens leaked to logs on panic
openshift/openshift-apiserver: oauthtokens leaked to logs on panic
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked OAuthToken to log into the API Server with the leaked token.
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked OAuthToken to log into the API Server with the leaked token.
Statement: OAuthTokens are only valid for 1 day by default
GHSA
GHSA-3cmv-p7jw-h3fg: A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server pan
ghsa_unreviewed·2022-05-24
CVE-2020-10752 [MEDIUM] CWE-400 GHSA-3cmv-p7jw-h3fg: A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server pan
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked OAuthToken to log into the API Server with the leaked token.
No detection rules found.
No public exploits indexed.
https://github.com/openshift/enhancements/pull/323https://github.com/openshift/origin/blob/master/vendor/k8s.io/kubernetes/staging/src/k8s.io/apiserver/pkg/server/filters/wrap.go#L39https://github.com/openshift/enhancements/pull/323https://github.com/openshift/origin/blob/master/vendor/k8s.io/kubernetes/staging/src/k8s.io/apiserver/pkg/server/filters/wrap.go#L39
2020-06-12
Published