CVE-2019-19335

MEDIUM

OpenShift 4.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials used to authenticate to the OpenShift API server, and are incorrectly assigned word-readable permissions. ose-installer as shipped in Openshift 4.2 is vulnerable.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19335

Scores

CVSS v3 4.4
EPSS 0.0009
EPSS Percentile 26.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-732
Status published
Products (2)
redhat/openshift 4.0
redhat/openshift 4.2
Published Mar 18, 2020
Tracked Since Feb 18, 2026