Vulnerability Description
Redpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk binary logs an AWS Access Key ID and Secret in cleartext to standard output, allowing a local user to view the key in the console, or in Kubernetes logs if stdout output is collected. The fixed versions are 22.3.12, 22.2.10, and 22.1.12.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redpanda | Redpanda | >= 22.1.0, < 22.1.12 |
Related Weaknesses (CWE)
References
- https://github.com/redpanda-data/redpanda/pull/8339ExploitPatchVendor Advisory
- https://github.com/redpanda-data/redpanda/pull/8339ExploitPatchVendor Advisory
FAQ
What is CVE-2023-24619?
CVE-2023-24619 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Redpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk binary logs an AWS Access Key ID and Secret in cleartext to standard output, allowing a local user to v...
How severe is CVE-2023-24619?
CVE-2023-24619 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-24619?
Check the references section above for vendor advisories and patch information. Affected products include: Redpanda Redpanda.