CVE-2020-8565

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
07/12/2020
Last modified:
08/12/2020

Description

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.17.0 (including) 1.17.13 (including)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.18.0 (including) 1.18.10 (including)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.19.0 (including) 1.19.3 (including)