Generation of Error Message Containing Sensitive Information
CVE-2019-11252
Summary
The Kubernetes kube-controller-manager in versions 1.x prior to v1.18.0-beta.2 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- LOW
- HIGH
- NONE
CWE-209 - Generation of Error Message Containing Sensitive Information
The software generates an error message that includes sensitive information about its environment, users, or associated data.
References
Advisory Timeline
- Published