Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.7 Go

Kubernetes Sensitive Information leak via Log File

GHSA-8mjg-8c8g-6h85 · CVE-2020-8564 · GO-2021-0066

Published · Modified

Description

In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.

Ready to move

Start Securing

Free, no credit card | First findings in minutes