5.5
CVSSv3

CVE-2020-8566

Published: 07/12/2020 Updated: 29/03/2021
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, < v1.17.13.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kubernetes kubernetes

Vendor Advisories

Synopsis Moderate: OpenShift Container Platform 4612 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4612 is now available withupdates to packages and images that fix several bugsThis release includes a security update for Red Hat ...
Debian Bug report logs - #972341 CVE-2020-8564 CVE-2020-8565 CVE-2020-8566 Package: src:kubernetes; Maintainer for src:kubernetes is Janos Lenart &lt;ocsi@debianorg&gt;; Reported by: Moritz Muehlenhoff &lt;jmm@debianorg&gt; Date: Fri, 16 Oct 2020 12:54:01 UTC Severity: important Tags: security Found in version kubernetes/118 ...
Debian Bug report logs - #972649 CVE-2020-8565 Package: src:kubernetes; Maintainer for src:kubernetes is Janos Lenart &lt;ocsi@debianorg&gt;; Reported by: Moritz Muehlenhoff &lt;jmm@debianorg&gt; Date: Fri, 16 Oct 2020 12:54:01 UTC Severity: important Tags: security Found in versions kubernetes/1186-1, kubernetes/1193-1 ...