-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The commit diff shows these functions originally contained klog.Errorf() calls that logged the raw 'contents' parameter (malformed docker config data) during JSON parsing errors. This would leak secrets when logging level >=4. The patch removes the %q format specifier that logged file contents and replaces it with generic error messages. The added test cases in config_test.go verify error handling without exposing sensitive data.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/kubernetes/kubernetes | go | >= 1.19.0, < 1.19.3 | 1.19.3 |
| github.com/kubernetes/kubernetes | go | >= 1.18.0, < 1.18.10 | 1.18.10 |
| github.com/kubernetes/kubernetes |
| go |
| < 1.17.13 |
| 1.17.13 |
| k8s.io/kubernetes | go | < 1.20.0-alpha.1 | 1.20.0-alpha.1 |
Ongoing coverage of React2Shell