In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.
References
Link | Resource |
---|---|
https://github.com/kubernetes/kubernetes/issues/95623 | Third Party Advisory |
https://groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ | Mailing List Patch Third Party Advisory |
https://github.com/kubernetes/kubernetes/issues/95623 | Third Party Advisory |
https://groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ | Mailing List Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:39
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 2.1
v3 : 4.7 |
References | () https://github.com/kubernetes/kubernetes/issues/95623 - Third Party Advisory | |
References | () https://groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ - Mailing List, Patch, Third Party Advisory |
Information
Published : 2020-12-07 22:15
Updated : 2024-11-21 05:39
NVD link : CVE-2020-8565
Mitre link : CVE-2020-8565
CVE.ORG link : CVE-2020-8565
JSON object : View
Products Affected
kubernetes
- kubernetes
CWE
CWE-532
Insertion of Sensitive Information into Log File