CVE-2019-19335: Red Hat Openshift

Medium severity, CVSS 4.4. EPSS: 0.3% chance of exploitation in the next 30 days.

During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials used to authenticate to the OpenShift API server, and are incorrectly assigned word-readable permissions. ose-installer as shipped in Openshift 4.2 is vulnerable.

Affected products

  • Red Hat Openshift: version 4.0 only; version 4.2 only

Published 2020-03-18. Last modified 2026-06-17.