CVE-2019-11250: Kubernetes
Medium severity, CVSS 6.5. EPSS: 1.8% chance of exploitation in the next 30 days.
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
Affected products
- Kubernetes Kubernetes: before 1.15.3 (fixed in 1.15.3); version 1.15.3 only; version 1.15.4 only; version 1.16.0 only
- Red Hat Openshift Container Platform: version 3.11 only; version 4.1 only
Published 2019-08-29. Last modified 2026-06-17.