Kubernetes did not effectively clear service account credentials in k8s.io/kubernetes
Kubernetes did not effectively clear service account credentials in k8s.io/kubernetes
02 / AFFECTED SOFTWARE
Affected packages
12 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Kubernetes did not effectively clear service account credentials in k8s.io/kubernetes
In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not effectively clear service account credentials loaded using rest.InClusterConfig()
In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not effectively clear service account credentials loaded using rest.InClusterConfig()
05 / REFERENCES
Further evidence
- https://github.com/advisories/GHSA-gc2p-g4fg-29vh
- https://github.com/kubernetes/kubernetes/issues/76797
- https://security.netapp.com/advisory/ntap-20190509-0002
- https://github.com/kubernetes/kubernetes
- https://nvd.nist.gov/vuln/detail/CVE-2019-11243
- http://www.securityfocus.com/bid/108053
- https://security.netapp.com/advisory/ntap-20190509-0002/