In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.
References
Link | Resource |
---|---|
https://github.com/kubernetes/kubernetes/issues/95623 | Third Party Advisory |
https://groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ | Mailing List Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-12-07 14:15
Updated : 2020-12-08 11:51
NVD link : CVE-2020-8565
Mitre link : CVE-2020-8565
JSON object : View
CWE
CWE-532
Insertion of Sensitive Information into Log File
Products Affected
kubernetes
- kubernetes