VYPR
Moderate severityNVD Advisory· Published Dec 7, 2020· Updated Sep 16, 2024

Secret leaks in logs for vSphere Provider kube-controller-manager

CVE-2020-8563

Description

In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/kubernetes/kubernetesGo
< 1.19.31.19.3

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.