Medium severity4.7NVD Advisory· Published Dec 7, 2020· Updated Jun 17, 2026
CVE-2020-8563
CVE-2020-8563
Description
In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/kubernetes/kubernetesGo | < 1.19.3 | 1.19.3 |
Affected products
4cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*range: <1.19.3
- (no CPE)range: < 1.19.3
- ghsa-coords2 versionspkg:golang/github.com/kubernetes/kubernetespkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweed
< 1.19.3+ 1 more
- (no CPE)range: < 1.19.3
- (no CPE)range: < 0.0.20250807T150727-1.1
Patches
Vulnerability mechanics
References
10- groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJnvdMailing ListPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-5xfg-wv98-264mghsaADVISORY
- github.com/kubernetes/kubernetes/issues/95621nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-8563ghsaADVISORY
- security.netapp.com/advisory/ntap-20210122-0006/nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cgighsaWEB
- github.com/kubernetes/kubernetes/pull/95236ghsaWEB
- github.com/kubernetes/kubernetes/pull/95236/commits/247f6dd09299bc7893c1e0affea11c0255025b96ghsaWEB
- groups.google.com/g/kubernetes-announce/c/ScdmyORnPDkghsaWEB
- security.netapp.com/advisory/ntap-20210122-0006ghsaWEB
News mentions
0No linked articles in our index yet.