CVE-2020-8566Log File Information Exposure in Kubernetes

Severity
5.5MEDIUMNVD
CNA4.7
EPSS
0.1%
top 74.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 7
Latest updateJun 4

Description

In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, < v1.17.13.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Gok8s.io/kubernetes1.18.01.18.10+2
CVEListV5kubernetes/kubernetes< 1.19.3+2
NVDkubernetes/kubernetes1.17.01.17.13+2
Gogithub.com/kubernetes_kubernetes1.18.01.18.10+2
Debiankubernetes/kubernetes< 1.19.3-1+3

Patches

🔴Vulnerability Details

5
OSV
Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes2024-06-04
GHSA
Sensitive Information leak via Log File in Kubernetes2024-04-24
OSV
Sensitive Information leak via Log File in Kubernetes2024-04-24
OSV
CVE-2020-8566: In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs2020-12-07
CVEList
Ceph RBD adminSecrets exposed in logs when loglevel >= 42020-12-07

📋Vendor Advisories

2
Red Hat
kubernetes: Ceph RBD adminSecrets exposed in logs when loglevel >= 42020-10-14
Debian
CVE-2020-8566: kubernetes - In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging lev...2020

💬Community

1
Bugzilla
CVE-2020-8566 kubernetes: Ceph RBD adminSecrets exposed in logs when loglevel >= 42020-10-09
CVE-2020-8566 — Log File Information Exposure | cvebase