| id: GO-2025-3645 |
| modules: |
| - module: k8s.io/kubernetes |
| versions: |
| - introduced: 1.12.0 |
| - fixed: 1.12.5 |
| - introduced: 1.13.0 |
| - fixed: 1.13.1 |
| vulnerable_at: 1.13.1-beta.0 |
| summary: Kubernetes did not effectively clear service account credentials in k8s.io/kubernetes |
| cves: |
| - CVE-2019-11243 |
| ghsas: |
| - GHSA-gc2p-g4fg-29vh |
| references: |
| - advisory: https://github.com/advisories/GHSA-gc2p-g4fg-29vh |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2019-11243 |
| - web: https://github.com/kubernetes/kubernetes/issues/76797 |
| - web: https://security.netapp.com/advisory/ntap-20190509-0002 |
| source: |
| id: GHSA-gc2p-g4fg-29vh |
| created: 2025-04-29T12:46:26.886806-04:00 |
| review_status: UNREVIEWED |