Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8564

Опубликовано: 14 окт. 2020
Источник: redhat
CVSS3: 5.3

Описание

In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.

A flaw was found in kubernetes. In Kubernetes, if the logging level is to at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This can occur with client tools like kubectl, or other components that use registry credentials in a docker config file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Storage 3heketiNot affected
Red Hat OpenShift Container Platform 3.11atomic-openshiftFixedRHSA-2021:319325.08.2021
Red Hat OpenShift Container Platform 4.4openshift4/ose-docker-builderFixedRHSA-2021:028103.02.2021
Red Hat OpenShift Container Platform 4.5openshift4/ose-docker-builderFixedRHSA-2020:535915.12.2020
Red Hat OpenShift Container Platform 4.6openshift-clientsFixedRHSA-2020:429727.10.2020
Red Hat OpenShift Container Platform 4.6openshiftFixedRHSA-2021:017225.01.2021
Red Hat OpenShift Container Platform 4.6openshift4/ose-docker-builderFixedRHSA-2020:525914.12.2020
Red Hat OpenShift Container Platform 4.6openshift4/ose-hyperkubeFixedRHSA-2021:017125.01.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-117
https://bugzilla.redhat.com/show_bug.cgi?id=1886637kubernetes: Docker config secrets leaked when file is malformed and loglevel >= 4

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 4 лет назад

In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.

CVSS3: 4.7
nvd
больше 4 лет назад

In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.

CVSS3: 4.7
debian
больше 4 лет назад

In Kubernetes clusters using a logging level of at least 4, processing ...

CVSS3: 4.7
github
больше 2 лет назад

Kubernetes Sensitive Information leak via Log File

5.3 Medium

CVSS3