Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-8565

Опубликовано: 07 дек. 2020
Источник: debian
EPSS Низкий

Описание

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kubernetesfixed1.20.0-1package

Примечания

  • https://github.com/kubernetes/kubernetes/pull/95316

  • https://groups.google.com/g/kubernetes-announce/c/ScdmyORnPDk

  • https://github.com/kubernetes/kubernetes/issues/95623

EPSS

Процентиль: 19%
0.00058
Низкий

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 4 лет назад

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

CVSS3: 5.3
redhat
больше 4 лет назад

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

CVSS3: 4.7
nvd
больше 4 лет назад

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

CVSS3: 5.5
msrc
3 месяца назад

Описание отсутствует

CVSS3: 4.7
github
больше 2 лет назад

Kubernetes client-go vulnerable to Sensitive Information Leak via Log File

EPSS

Процентиль: 19%
0.00058
Низкий