Vulnerability Details CVE-2020-8565
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.6%
CVSS Severity
CVSS v3 Score 4.7
CVSS v2 Score 2.1
Products affected by CVE-2020-8565
-
cpe:2.3:a:kubernetes:kubernetes:1.17.0
-
cpe:2.3:a:kubernetes:kubernetes:1.17.1
-
cpe:2.3:a:kubernetes:kubernetes:1.17.10
-
cpe:2.3:a:kubernetes:kubernetes:1.17.11
-
cpe:2.3:a:kubernetes:kubernetes:1.17.12
-
cpe:2.3:a:kubernetes:kubernetes:1.17.13
-
cpe:2.3:a:kubernetes:kubernetes:1.17.2
-
cpe:2.3:a:kubernetes:kubernetes:1.17.3
-
cpe:2.3:a:kubernetes:kubernetes:1.17.4
-
cpe:2.3:a:kubernetes:kubernetes:1.17.5
-
cpe:2.3:a:kubernetes:kubernetes:1.17.6
-
cpe:2.3:a:kubernetes:kubernetes:1.17.7
-
cpe:2.3:a:kubernetes:kubernetes:1.17.8
-
cpe:2.3:a:kubernetes:kubernetes:1.17.9
-
cpe:2.3:a:kubernetes:kubernetes:1.18.0
-
cpe:2.3:a:kubernetes:kubernetes:1.18.1
-
cpe:2.3:a:kubernetes:kubernetes:1.18.10
-
cpe:2.3:a:kubernetes:kubernetes:1.18.2
-
cpe:2.3:a:kubernetes:kubernetes:1.18.3
-
cpe:2.3:a:kubernetes:kubernetes:1.18.4
-
cpe:2.3:a:kubernetes:kubernetes:1.18.5
-
cpe:2.3:a:kubernetes:kubernetes:1.18.6
-
cpe:2.3:a:kubernetes:kubernetes:1.18.7
-
cpe:2.3:a:kubernetes:kubernetes:1.18.8
-
cpe:2.3:a:kubernetes:kubernetes:1.18.9
-
cpe:2.3:a:kubernetes:kubernetes:1.19.0
-
cpe:2.3:a:kubernetes:kubernetes:1.19.1
-
cpe:2.3:a:kubernetes:kubernetes:1.19.2
-
cpe:2.3:a:kubernetes:kubernetes:1.19.3