| Vulnerability Name: | CVE-2020-8564 (CCN-189924) | ||||||||||||
| Assigned: | 2020-10-16 | ||||||||||||
| Published: | 2020-10-16 | ||||||||||||
| Updated: | 2021-03-29 | ||||||||||||
| Summary: | In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13. | ||||||||||||
| CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.1 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-532 | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2020-8564 Source: XF Type: UNKNOWN kubernetes-cve20208564-info-disc(189924) Source: CONFIRM Type: Third Party Advisory https://github.com/kubernetes/kubernetes/issues/95622 Source: CCN Type: kubernetes GIT Repository [credentialprovider] avoid potential secret leaking while reading .dockercfg #94712 Source: MLIST Type: Mailing List, Patch, Third Party Advisory Multiple secret leaks when verbose logging is enabled Source: CCN Type: oss-sec Mailing List, Fri, 16 Oct 2020 09:55:45 +1000 Kubernetes: Multiple secret leaks when verbose logging is enabled Source: CONFIRM Type: Third Party Advisory https://security.netapp.com/advisory/ntap-20210122-0006/ Source: CCN Type: IBM Security Bulletin 6417487 (Cloud Private) IBM Cloud Private is vulnerable to Kubernetes vulnerabilities (CVE-2020-8566, CVE-2020-8565, CVE-2020-8563, CVE-2020-8564) Source: CCN Type: IBM Security Bulletin 6452959 (Spectrum Discover) Vulnerabilities in the Python, Docker, and ICP affect IBM Spectrum Discover Source: CCN Type: IBM Security Bulletin 6599703 (Db2 On Openshift) Multiple vulnerabilities affect IBM Db2 On Openshift and IBM Db2 and Db2 Warehouse on Cloud Pak for Data Source: CCN Type: IBM Security Bulletin 6833266 (CICS TX Standard) IBM CICS TX Standard is vulnerable to multiple vulnerabilities in Golang Go. Source: CCN Type: IBM Security Bulletin 6833268 (CICS TX Advanced) IBM CICS TX Advanced is vulnerable to multiple vulnerabilities in Golang Go. | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||