5.5
CVSSv3

CVE-2020-8565

Published: 07/12/2020 Updated: 08/12/2020
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 188
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kubernetes kubernetes

Vendor Advisories

Debian Bug report logs - #972341 CVE-2020-8564 CVE-2020-8565 CVE-2020-8566 Package: src:kubernetes; Maintainer for src:kubernetes is Janos Lenart &lt;ocsi@debianorg&gt;; Reported by: Moritz Muehlenhoff &lt;jmm@debianorg&gt; Date: Fri, 16 Oct 2020 12:54:01 UTC Severity: important Tags: security Found in version kubernetes/118 ...
Debian Bug report logs - #972649 CVE-2020-8565 Package: src:kubernetes; Maintainer for src:kubernetes is Janos Lenart &lt;ocsi@debianorg&gt;; Reported by: Moritz Muehlenhoff &lt;jmm@debianorg&gt; Date: Fri, 16 Oct 2020 12:54:01 UTC Severity: important Tags: security Found in versions kubernetes/1186-1, kubernetes/1193-1 ...