CVE-2020-8563 describes a vulnerability in Kubernetes clusters leveraging vSphere as a cloud provider, where vSphere cloud credentials can be inadvertently exposed in the cloud controller manager's logs if the logging level is set to 4 or higher. This affects Kubernetes versions prior to v1.19.3. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring low privileges, and leading to high confidentiality impact through information disclosure. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.19.3CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Sensitive Information leak via Log File in Kubernetes
Apr 24, 2024Secret leaks in logs for vSphere Provider kube-controller-manager
Dec 8, 2020kubernetes: Secret leaks in kube-controller-manager when using vSphere Provider
Oct 14, 2020Kubernetes Secret Leaks in Logs
Jan 1, 2020Secret leaks in kube-controller-manager when using vSphere provider
Secret leaks in kube-controller-manager when using vSphere provider
Secret leaks in kube-controller-manager when using vSphere provider
Secret leaks in kube-controller-manager when using vSphere provider
The Kubernetes project recently discovered several issues that allow for the exposure of secret data when verbose logging options are enabled.
Kubernetes Secret Data Exposure in Logs