Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-8565

Опубликовано: 07 дек. 2020
Источник: debian
EPSS Низкий

Описание

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kubernetesfixed1.20.0-1package

Примечания

  • https://github.com/kubernetes/kubernetes/pull/95316

  • https://groups.google.com/g/kubernetes-announce/c/ScdmyORnPDk

  • https://github.com/kubernetes/kubernetes/issues/95623

EPSS

Процентиль: 13%
0.00044
Низкий

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 5 лет назад

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

CVSS3: 5.3
redhat
больше 5 лет назад

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

CVSS3: 4.7
nvd
около 5 лет назад

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

CVSS3: 5.5
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 4.7
github
почти 3 года назад

Kubernetes client-go vulnerable to Sensitive Information Leak via Log File

EPSS

Процентиль: 13%
0.00044
Низкий