Sploitus

CVE-2019-14854

No indexed exploits for CVE-2019-14854 yet

OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.

Redhat Openshift Container Platform
= 4.1, 4.2
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.8% (53th percentile)
Weakness
CWE-532, CWE-117
NVD status
Modified
Published
2020-01-07
CVE-2019-14854 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2019-14854 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2019-14854 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.