ALT-PU-2021-1495-1
Package kubernetes updated to version 1.20.2-alt1 for branch p9 in task 265985.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-8563
In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.
- https://github.com/kubernetes/kubernetes/issues/95621
- https://github.com/kubernetes/kubernetes/issues/95621
- Multiple secret leaks when verbose logging is enabled
- Multiple secret leaks when verbose logging is enabled
- https://security.netapp.com/advisory/ntap-20210122-0006/
- https://security.netapp.com/advisory/ntap-20210122-0006/
Modified: 2024-11-21
CVE-2020-8564
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.
- https://github.com/kubernetes/kubernetes/issues/95622
- https://github.com/kubernetes/kubernetes/issues/95622
- Multiple secret leaks when verbose logging is enabled
- Multiple secret leaks when verbose logging is enabled
- https://security.netapp.com/advisory/ntap-20210122-0006/
- https://security.netapp.com/advisory/ntap-20210122-0006/
Modified: 2024-11-21
CVE-2020-8565
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.
Modified: 2024-11-21
CVE-2020-8566
In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, < v1.17.13.
- https://github.com/kubernetes/kubernetes/issues/95624
- https://github.com/kubernetes/kubernetes/issues/95624
- Multiple secret leaks when verbose logging is enabled
- Multiple secret leaks when verbose logging is enabled
- https://security.netapp.com/advisory/ntap-20210122-0006/
- https://security.netapp.com/advisory/ntap-20210122-0006/