CVE-2020-8565: Insertion of Sensitive Information into Log File
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.
References
- github.com/advisories/GHSA-8cfg-vx93-jvxw
- github.com/kubernetes/kubernetes/commit/e99df0e5a75eb6e86123b56d53e9b7ca0fd00419
- github.com/kubernetes/kubernetes/issues/95623
- github.com/kubernetes/kubernetes/pull/95316
- groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ
- nvd.nist.gov/vuln/detail/CVE-2020-8565
- pkg.go.dev/vuln/GO-2021-0064
Detect and mitigate CVE-2020-8565 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →