CVE-2020-8563Log File Information Exposure in Kubernetes

Severity
5.5MEDIUMNVD
CNA4.7
EPSS
0.1%
top 77.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 7
Latest updateJun 5

Description

In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Patches

🔴Vulnerability Details

5
OSV
Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes2024-06-05
GHSA
Sensitive Information leak via Log File in Kubernetes2024-04-24
OSV
Sensitive Information leak via Log File in Kubernetes2024-04-24
CVEList
Secret leaks in logs for vSphere Provider kube-controller-manager2020-12-07
OSV
CVE-2020-8563: In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the clou2020-12-07

📋Vendor Advisories

3
Microsoft
Secret leaks in logs for vSphere Provider kube-controller-manager2020-12-08
Red Hat
kubernetes: Secret leaks in kube-controller-manager when using vSphere Provider2020-10-14
Debian
CVE-2020-8563: kubernetes - In Kubernetes clusters using VSphere as a cloud provider, with a logging level s...2020

💬Community

1
Bugzilla
CVE-2020-8563 kubernetes: Secret leaks in kube-controller-manager when using vSphere Provider2020-10-09
CVE-2020-8563 — Log File Information Exposure | cvebase