Описание
The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.
A flaw was found in Kubernetes that allows the logging of credentials when mounting AzureFile and CephFS volumes. This flaw allows an attacker to access kubelet logs, read the credentials, and use them to access other services. The highest threat from this vulnerability is to confidentiality.
Отчет
OpenShift Container Platform (OCP) included the upstream patch for this flaw in the release of version 4.5. Prior versions are affected as OCP 4 supports AzureFile volumes and OCP 3 supports both AzureFile and CephFS volumes. OCP clusters not using these volume types are not vulnerable.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Will not fix | ||
Red Hat Openshift Container Storage 4 | ocs4/cephcsi-rhel8 | Not affected | ||
Red Hat Openshift Container Storage 4 | ocs4/ocs-must-gather-rhel8 | Not affected | ||
Red Hat Openshift Container Storage 4 | ocs4/ocs-rhel8-operator | Not affected | ||
Red Hat Openshift Container Storage 4 | ocs4/rook-ceph-rhel8-operator | Not affected | ||
Red Hat Storage 3 | heketi | Affected | ||
Red Hat OpenShift Container Platform 4.5 | openshift4/ose-hyperkube | Fixed | RHSA-2020:2412 | 13.07.2020 |
Red Hat OpenShift Container Platform 4.5 | openshift | Fixed | RHSA-2020:2413 | 13.07.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.
The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.
The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulne ...
EPSS
5.9 Medium
CVSS3