Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8565

Опубликовано: 14 окт. 2020
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

A flaw was found in kubernetes. In Kubernetes, if the logging level is to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. Previously, CVE-2019-11250 was assigned for the same issue for logging levels of at least 4.

Отчет

OpenShift Container Platform 4 does not support LogLevels higher than 8 (via 'TraceAll'), and is therefore not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11atomic-openshiftWill not fix
Red Hat OpenShift Container Platform 4openshiftNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-hyperkube-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift-clientsNot affected
Red Hat Openshift Container Storage 4mcgAffected
Red Hat Storage 3heketiAffected
Red Hat Storage 3rhgs3/rhgs-gluster-block-prov-rhel7Affected
Red Hat OpenShift Container Storage 4.7.0 on RHEL-8ocs4/rook-ceph-rhel8-operatorFixedRHSA-2021:204119.05.2021
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8ocs4/cephcsi-rhel8FixedRHBA-2021:300303.08.2021
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8ocs4/mcg-core-rhel8FixedRHBA-2021:300303.08.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-117
https://bugzilla.redhat.com/show_bug.cgi?id=1886638kubernetes: Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9

EPSS

Процентиль: 19%
0.0006
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 4 лет назад

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

CVSS3: 4.7
nvd
больше 4 лет назад

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

CVSS3: 5.5
msrc
4 месяца назад

Описание отсутствует

CVSS3: 4.7
debian
больше 4 лет назад

In Kubernetes, if the logging level is set to at least 9, authorizatio ...

CVSS3: 4.7
github
больше 2 лет назад

Kubernetes client-go vulnerable to Sensitive Information Leak via Log File

EPSS

Процентиль: 19%
0.0006
Низкий

5.3 Medium

CVSS3