Vulnerability Details CVE-2020-8564
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.2%
CVSS Severity
CVSS v3 Score 4.7
CVSS v2 Score 2.1
Products affected by CVE-2020-8564
-
cpe:2.3:a:kubernetes:kubernetes:1.17.0
-
cpe:2.3:a:kubernetes:kubernetes:1.17.1
-
cpe:2.3:a:kubernetes:kubernetes:1.17.10
-
cpe:2.3:a:kubernetes:kubernetes:1.17.11
-
cpe:2.3:a:kubernetes:kubernetes:1.17.12
-
cpe:2.3:a:kubernetes:kubernetes:1.17.2
-
cpe:2.3:a:kubernetes:kubernetes:1.17.3
-
cpe:2.3:a:kubernetes:kubernetes:1.17.4
-
cpe:2.3:a:kubernetes:kubernetes:1.17.5
-
cpe:2.3:a:kubernetes:kubernetes:1.17.6
-
cpe:2.3:a:kubernetes:kubernetes:1.17.7
-
cpe:2.3:a:kubernetes:kubernetes:1.17.8
-
cpe:2.3:a:kubernetes:kubernetes:1.17.9
-
cpe:2.3:a:kubernetes:kubernetes:1.18.0
-
cpe:2.3:a:kubernetes:kubernetes:1.18.1
-
cpe:2.3:a:kubernetes:kubernetes:1.18.2
-
cpe:2.3:a:kubernetes:kubernetes:1.18.3
-
cpe:2.3:a:kubernetes:kubernetes:1.18.4
-
cpe:2.3:a:kubernetes:kubernetes:1.18.5
-
cpe:2.3:a:kubernetes:kubernetes:1.18.6
-
cpe:2.3:a:kubernetes:kubernetes:1.18.7
-
cpe:2.3:a:kubernetes:kubernetes:1.18.8
-
cpe:2.3:a:kubernetes:kubernetes:1.18.9
-
cpe:2.3:a:kubernetes:kubernetes:1.19.0
-
cpe:2.3:a:kubernetes:kubernetes:1.19.1
-
cpe:2.3:a:kubernetes:kubernetes:1.19.2