Inclusion of Sensitive Information in Log Files in Kubernetes - CVE-2020-8565

 

Inclusion of Sensitive Information in Log Files in Kubernetes - CVE-2020-8565

Published: June 30, 2022


Vulnerability identifier: #VU64820
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8565
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to authorization and bearer tokens will be written to log files if the logging level is set to at least 9. A local user can read the log files and gain access to sensitive data.


Affected software

Kubernetes
IBM Observability with Instana
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Maximo Application Suite
DB2 Data Management Console
IBM Cloud Pak for Watson AIOps
DataStage on Cloud Pak for Data
Robotic Process Automation for Cloud Pak
IBM Edge Application Manager
watsonx.data
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM DB2
mcg (Red Hat package)

How to mitigate CVE-2020-8565

Install updates from vendor's website.

Kubernetes - addressed in versions 1.17.16, 1.18.14, 1.19.6, 1.20.0
DB2 Data Management Console - update to 3.1.13
Netcool Operations Insight - update to 1.6.10
watsonx.data - update to 2.0.1
IBM Cloud Pak for Watson AIOps - update to 4.8.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.9.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.0
IBM DB2 - update to 5.0
DataStage on Cloud Pak for Data - update to 5.0.0
mcg (Red Hat package) - update to 5.9.0-28.61dcf87.5.9.el8
IBM Maximo Application Suite - addressed in versions 8.10.16, 8.11.14, 9.0.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.10, 23.0.10

External References

Related Security Bulletins