FlawAtlas
Search the atlas
CVE-2019-11243 High

Kubernetes did not effectively clear service account credentials in k8s.io/kubernetes

Kubernetes did not effectively clear service account credentials in k8s.io/kubernetes

Exploit probability 1.5%
Published May 5, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

12 explicit affected versions

Go k8s.io/kubernetes
Go k8s.io/kubernetes

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2025-3645

Kubernetes did not effectively clear service account credentials in k8s.io/kubernetes

View original source
Open Source Vulnerabilities GHSA-gc2p-g4fg-29vh

In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not effectively clear service account credentials loaded using rest.InClusterConfig()

View original source
Open Source Vulnerabilities CVE-2019-11243

In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not effectively clear service account credentials loaded using rest.InClusterConfig()

View original source

05 / REFERENCES

Further evidence