Vulnerability record · CVE-2019-10165 · published 30 July 2019
CVE-2019-10165: Redhat openshift container platform sensitive information in log file vulnerability
Redhat · Openshift Container Platform
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.
Description
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10165 | Issue TrackingPatchVendor Advisory |
| https://github.com/openshift/cluster-kube-apiserver-operator/pull/499/ | PatchThird Party Advisory |
| https://github.com/openshift/cluster-openshift-apiserver-operator/pull/205 | PatchThird Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10165 | Issue TrackingPatchVendor Advisory |
| https://github.com/openshift/cluster-kube-apiserver-operator/pull/499/ | PatchThird Party Advisory |
| https://github.com/openshift/cluster-openshift-apiserver-operator/pull/205 | PatchThird Party Advisory |
Track CVE-2019-10165 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-10165), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.