DirectorySecurity Advisories
Sign In
Security Advisories

CGA-3qf3-94gx-766h

Published

Last updated

https://images.chainguard.dev/security/CGA-3qf3-94gx-766h
Package

kubeflow-pipelines

Latest Update
Not affected
Aliases
  • CVE-2019-11250
  • GHSA-jmrx-5g74-6v2f

Severity

6.5

Medium

CVSS V3

Summary

Kubernetes client-go library logs may disclose credentials to unauthorized users

Description

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images