CVE-2020-8566 describes a medium-severity vulnerability in Kubernetes clusters utilizing Ceph RBD as a storage provisioner. When the kube-controller-manager's logging level is set to 4 or higher, Ceph RBD admin secrets can be inadvertently written to logs during the provisioning of persistent claims. This affects Kubernetes versions prior to v1.19.3, v1.18.10, and v1.17.13. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and resulting in high confidentiality impact due to potential secret exposure. There is no impact on integrity or availability. Currently, there is no evidence of active exploitation, nor is exploit code publicly available through platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, aligning with the typical lack of attention for a large percentage of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.17.0, < 1.17.13CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
>= 1.18.0, < 1.18.10CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
>= 1.19.0, < 1.19.3CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Sensitive Information leak via Log File in Kubernetes
Apr 24, 2024kubernetes: Ceph RBD adminSecrets exposed in logs when loglevel >= 4
Oct 14, 2020Kubernetes Secret Leaks in Logs
Jan 1, 2020Kubernetes Secret Data Exposure in Logs
Ceph RBD adminSecrets exposed in logs when loglevel >= 4
Ceph RBD adminSecrets exposed in logs when loglevel >= 4
Ceph RBD adminSecrets exposed in logs when loglevel >= 4
Ceph RBD adminSecrets exposed in logs when loglevel >= 4
The Kubernetes project recently discovered several issues that allow for the exposure of secret data when verbose logging options are enabled.