{"schema_version":"1.9.0","id":"GHSA-gc2p-g4fg-29vh","published":"2022-05-24T16:44:02Z","modified":"2025-05-05T16:41:57.914022Z","aliases":["CVE-2019-11243","GO-2025-3645"],"summary":"Kubernetes did not effectively clear service account credentials","details":"In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not effectively clear service account credentials loaded using rest.InClusterConfig()","affected":[{"package":{"name":"k8s.io/kubernetes","ecosystem":"Go","purl":"pkg:golang/k8s.io/kubernetes"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.12.0"},{"fixed":"1.12.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gc2p-g4fg-29vh/GHSA-gc2p-g4fg-29vh.json"}},{"package":{"name":"k8s.io/kubernetes","ecosystem":"Go","purl":"pkg:golang/k8s.io/kubernetes"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.13.0"},{"fixed":"1.13.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gc2p-g4fg-29vh/GHSA-gc2p-g4fg-29vh.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11243"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/issues/76797"},{"type":"PACKAGE","url":"https://github.com/kubernetes/kubernetes"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20190509-0002"}],"database_specific":{"cwe_ids":["CWE-212","CWE-271"],"github_reviewed":true,"github_reviewed_at":"2025-04-24T17:41:45Z","nvd_published_at":"2019-04-22T15:29:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}