| - module: k8s.io/client-go |
| vulnerable_at: 0.20.0-alpha.1 |
| - package: k8s.io/client-go/transport |
| - basicAuthRoundTripper.RoundTrip |
| - bearerAuthRoundTripper.RoundTrip |
| - debuggingRoundTripper.RoundTrip |
| - impersonatingRoundTripper.RoundTrip |
| - userAgentRoundTripper.RoundTrip |
| - module: k8s.io/kubernetes |
| vulnerable_at: 1.20.0-alpha.1 |
| - package: k8s.io/kubernetes/staging/src/k8s.io/client-go/transport |
| skip_fix: 'TODO: revisit this reason (module does not contain package k8s.io/kubernetes/staging/src/k8s.io/client-go/transport)' |
| summary: Unauthorized credential disclosure in k8s.io/kubernetes and k8s.io/client-go |
| Authorization tokens may be inappropriately logged if the verbosity level is set |
| published: 2021-04-14T20:04:52Z |
| - fix: https://github.com/kubernetes/kubernetes/pull/95316 |
| - fix: https://github.com/kubernetes/kubernetes/commit/e99df0e5a75eb6e86123b56d53e9b7ca0fd00419 |
| - web: https://github.com/kubernetes/kubernetes/issues/95623 |