{"id":"CVE-2019-11243","aliases":["GHSA-gc2p-g4fg-29vh","GO-2025-3645"],"url":"https://o3.security/vulnerability/CVE-2019-11243","summary":"Kubernetes did not effectively clear service account credentials","details":"In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not effectively clear service account credentials loaded using rest.InClusterConfig()","published":"2019-04-22T15:29:00.790Z","modified":"2026-08-07T14:48:29.988259Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"k8s.io/kubernetes","fixedVersion":"1.12.5"},{"ecosystem":"Go","name":"k8s.io/kubernetes","fixedVersion":"1.13.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/108053"},{"type":"ADVISORY","url":"https://github.com/kubernetes/kubernetes/issues/76797"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20190509-0002/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:48:29.988259Z"}}