Information Exposure Through an Error Message in Kubernetes - CVE-2019-11252
Published: June 30, 2022
Kubernetes
Kubernetes
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists in kube-controller-manager due to credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes. A remote user can gain access to kubelet logs, read the credentials, and use them to access other services.