← Back

CVE-2020-8566

nvd nist
Published: Dec 7, 2020Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, < v1.17.13.

Affected (3)

1 product
Kubernetes
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Kubernetes
From 1.17.0 to 1.17.13
From 1.18.0 to 1.18.10
From 1.19.0 to 1.19.3

References (6)

Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Mailing ListPatchThird Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.