Information disclosure in Google Kubernetes Engine - CVE-2019-10365
Published: October 22, 2019
Google Kubernetes Engine
Detailed vulnerability description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to the affected plugin creates a temporary file named ".kube…config" containing a temporary access token in the project workspace. A remote authenticated user with Job/Read permission can access the file via workspace browsers, or accidentally archived, disclosing the token.