CVE-2019-11250: Kubernetes

Medium severity, CVSS 6.5. EPSS: 1.8% chance of exploitation in the next 30 days.

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

Affected products

  • Kubernetes Kubernetes: before 1.15.3 (fixed in 1.15.3); version 1.15.3 only; version 1.15.4 only; version 1.16.0 only
  • Red Hat Openshift Container Platform: version 3.11 only; version 4.1 only

Published 2019-08-29. Last modified 2026-06-17.