Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 733804 (CVE-2019-11252) - sys-cluster/{kubernetes,kube-controller-manager}: Potential credential leakage in kube-controller-manager logs (CVE-2019-11252)
Summary: sys-cluster/{kubernetes,kube-controller-manager}: Potential credential leakag...
Status: RESOLVED FIXED
Alias: CVE-2019-11252
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://github.com/kubernetes/kuberne...
Whiteboard: C4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-07-24 18:04 UTC by John Helmert III
Modified: 2021-06-12 18:59 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-07-24 18:04:29 UTC
CVE-2019-11252:

The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.



Maintainer, it's unclear from $URL whether our versions have a cherry-picked fix so please advise on this.
Comment 1 William Hubbs gentoo-dev 2020-07-24 19:02:18 UTC
We now have 1.16.13.
I don't know whether the 1.16 and 1.17 versions in the tree are
vulnerable or not, so I'll wait for a comment from the security team.
Comment 2 William Hubbs gentoo-dev 2020-07-24 19:14:08 UTC
I meant to list the other versions we have.
We currently have versions 1.16.13, 1.17.9 and 1.18.6.
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-10-24 15:34:23 UTC
It looks like this will not be backported to 1.16 or even 1.17 (see https://github.com/kubernetes/kubernetes/pull/89494#issuecomment-619260906, https://github.com/kubernetes/kubernetes/pull/88684#issuecomment-673731833). All versions of 1.18 and later appear to have the fix. William, is it possible at this point to drop the 1.17 branch from Gentoo?
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-06-12 18:59:10 UTC
Cleanup is done, trivial severity so no GLSA, all done!