Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-8563

20
FAUCET Score

CVE-2020-8563 describes a vulnerability in Kubernetes clusters leveraging vSphere as a cloud provider, where vSphere cloud credentials can be inadvertently exposed in the cloud controller manager's logs if the logging level is set to 4 or higher. This affects Kubernetes versions prior to v1.19.3. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring low privileges, and leading to high confidentiality impact through information disclosure. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.19.3CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.51%
Probability of exploitation in next 30 days
EPSS Percentile
40.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0050 is in the 92nd percentile among its peer group of 15,938 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (20)

check_pointpatch availablevia llm_extracted
View patch
chromepatch availablevia llm_extracted
View patch
gopatch availablevia ghsa
Product: github.com/kubernetes/kubernetesFixed in: 1.19.3
infiniflowpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 19107-16820Fixed in: 1.18.19-2
microsoftpatch availablevia msrc
Product: 19111-16820Fixed in: 1.18.17-5
microsoftpatch availablevia msrc
Product: cm1 kubernetes-1.18.17 1.18.17-6 on CBL Mariner 1.0Fixed in: 1.18.17-6
microsoftpatch availablevia msrc
Product: cm1 kubernetes-1.18.14 1.18.14-8 on CBL Mariner 1.0Fixed in: 1.18.14-8
microsoftpatch availablevia msrc
Product: cm1 kubernetes 1.18.17-5 on CBL Mariner 1.0Fixed in: 1.18.17-5
microsoftpatch availablevia msrc
Product: 19109-16820Fixed in: 1.18.17-6
microsoftpatch availablevia msrc
Product: 19108-16820Fixed in: 1.18.17-9
microsoftpatch availablevia msrc
Product: 19110-16820Fixed in: 1.18.14-8
microsoftpatch availablevia msrc
Product: cm1 kubernetes-1.18.19 1.18.19-2 on CBL Mariner 1.0Fixed in: 1.18.19-2
microsoftpatch availablevia msrc
Product: cm1 kubernetes-1.18.17 1.18.17-9 on CBL Mariner 1.0Fixed in: 1.18.17-9
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift-0:4.6.0-202012051246.p0.git.94231.efc9027.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: openshift4/ose-hyperkube:v4.7.0-202102130115.p0
View patch
vuepatch availablevia llm_extracted
View patch
denovendor investigatingvia llm_extracted
invoiceplanevendor investigatingvia llm_extracted
pjsipvendor investigatingvia llm_extracted

Vendor Advisories (10)

goGHSA-5xfg-wv98-264mmedium

Sensitive Information leak via Log File in Kubernetes

Apr 24, 2024
microsoft2020-Dec/CVE-2020-8563Moderate

Secret leaks in logs for vSphere Provider kube-controller-manager

Dec 8, 2020
redhatCVE-2020-8563Moderate

kubernetes: Secret leaks in kube-controller-manager when using vSphere Provider

Oct 14, 2020
pjsipllm-pjsip-e46c3193693fba02

Kubernetes Secret Leaks in Logs

Jan 1, 2020
chromellm-chrome-7d6d6870232921f9

Secret leaks in kube-controller-manager when using vSphere provider

check_pointllm-check_point-2db668a3028d7966

Secret leaks in kube-controller-manager when using vSphere provider

infiniflowllm-infiniflow-59cdea2f905483b0

Secret leaks in kube-controller-manager when using vSphere provider

vuellm-vue-9644bb05a042526f

Secret leaks in kube-controller-manager when using vSphere provider

invoiceplanellm-invoiceplane-3c5ff73033b981d7

The Kubernetes project recently discovered several issues that allow for the exposure of secret data when verbose logging options are enabled.

denollm-deno-becf568e3986408a

Kubernetes Secret Data Exposure in Logs

References

github.com / kubernetes/kubernetes/issues/95621
Third Party Advisory
groups.google.com / g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ
Mailing ListPatchThird Party Advisory
security.netapp.com / advisory/ntap-20210122-0006
Third Party Advisory