Sensitive Data Exposure in Openshift Container Platform
Moderate severity
Unreviewed
Published
May 17, 2021
to the GitHub Advisory Database
•
Updated Nov 12, 2023
Description
Published by the National Vulnerability Database
Nov 25, 2019
Published to the GitHub Advisory Database
May 17, 2021
Last updated
Nov 12, 2023
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
References