Inclusion of Sensitive Information in Log Files in Kubernetes - CVE-2020-8564

 

Inclusion of Sensitive Information in Log Files in Kubernetes - CVE-2020-8564

Published: December 7, 2020 / Updated: January 26, 2021


Vulnerability identifier: #VU48977
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8564
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to software stores sensitive information into log files. In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. A local user can read the log files and gain access to sensitive data.


Affected software

Kubernetes
skopeo (Red Hat package)
cri-o (Red Hat package)
atomic-openshift (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-cluster-autoscaler (Red Hat package)
golang-github-prometheus-alertmanager (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
atomic-openshift-metrics-server (Red Hat package)
atomic-openshift-node-problem-detector (Red Hat package)
openshift-enterprise-autoheal (Red Hat package)
atomic-openshift-web-console (Red Hat package)
atomic-openshift-descheduler (Red Hat package)
openshift-enterprise-cluster-capacity (Red Hat package)
golang-github-openshift-oauth-proxy (Red Hat package)
golang-github-prometheus-node_exporter (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
golang-github-prometheus-prometheus (Red Hat package)
atomic-openshift-dockerregistry (Red Hat package)
openshift-kuryr (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
Red Hat OpenShift Container Platform
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Pak for Watson AIOps
IBM CICS TX Standard
IBM CICS TX Advanced

How to mitigate CVE-2020-8564

Install updates from vendor's website.

Kubernetes - addressed in versions 1.17.13, 1.18.10, 1.19.3
skopeo (Red Hat package) - update to 1.1.1-3.rhaos4.6.el8
cri-o (Red Hat package) - addressed in versions 1.11.16-0.16.rhaos3.11.git54f9e69.el7, 1.19.1-4.rhaos4.6.git3846aab.el8
Red Hat OpenShift Container Platform - addressed in versions 3.11.501, 4.5.23, 4.6.8, 4.6.13
atomic-openshift (Red Hat package) - update to 3.11.501-1.git.0.f8c4746.el7
openshift-ansible (Red Hat package) - update to 3.11.501-1.git.0.5ea39b1.el7
atomic-openshift-cluster-autoscaler (Red Hat package) - update to 3.11.501-1.git.99b2acf.el7
golang-github-prometheus-alertmanager (Red Hat package) - update to 3.11.501-1.git.13de638.el7
atomic-openshift-service-idler (Red Hat package) - update to 3.11.501-1.git.39cfc66.el7
atomic-openshift-metrics-server (Red Hat package) - update to 3.11.501-1.git.f8bf728.el7
atomic-openshift-node-problem-detector (Red Hat package) - update to 3.11.501-1.git.c8f26da.el7
openshift-enterprise-autoheal (Red Hat package) - update to 3.11.501-1.git.f2f435d.el7
atomic-openshift-web-console (Red Hat package) - update to 3.11.501-1.git.fc3b323.el7
atomic-openshift-descheduler (Red Hat package) - update to 3.11.501-1.git.d435537.el7
openshift-enterprise-cluster-capacity (Red Hat package) - update to 3.11.501-1.git.22be164.el7
golang-github-openshift-oauth-proxy (Red Hat package) - update to 3.11.501-1.git.edebe84.el7
golang-github-prometheus-node_exporter (Red Hat package) - update to 3.11.501-1.git.609cd20.el7
atomic-enterprise-service-catalog (Red Hat package) - update to 3.11.501-1.git.2e6be86.el7
golang-github-prometheus-prometheus (Red Hat package) - update to 3.11.501-1.git.99aae51.el7
atomic-openshift-dockerregistry (Red Hat package) - update to 3.11.501-1.git.3571208.el7
openshift-kuryr (Red Hat package) - addressed in versions 3.11.501-1.git.c33a657.el7, 4.6.0-202101151835.p0.git.2220.40847e5.el8
openshift-clients (Red Hat package) - addressed in versions 4.6.0-202101160934.p0.git.3808.a1bca2f.el7, 4.6.0-202101160934.p0.git.3808.a1bca2f.el8
openshift (Red Hat package) - addressed in versions 4.6.0-202101160934.p0.git.94242.fc5242e.el7, 4.6.0-202101160934.p0.git.94242.fc5242e.el8
Red Hat Advanced Cluster Management for Kubernetes - update to 2.1.3
IBM Cloud Pak for Watson AIOps - update to 4.8.1
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5

External References

Related Security Bulletins