Vulnerability Details CVE-2020-8566
In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, < v1.17.13.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.4%
CVSS Severity
CVSS v3 Score 4.7
CVSS v2 Score 2.1
Products affected by CVE-2020-8566
-
cpe:2.3:a:kubernetes:kubernetes:1.17.0
-
cpe:2.3:a:kubernetes:kubernetes:1.17.1
-
cpe:2.3:a:kubernetes:kubernetes:1.17.10
-
cpe:2.3:a:kubernetes:kubernetes:1.17.11
-
cpe:2.3:a:kubernetes:kubernetes:1.17.12
-
cpe:2.3:a:kubernetes:kubernetes:1.17.2
-
cpe:2.3:a:kubernetes:kubernetes:1.17.3
-
cpe:2.3:a:kubernetes:kubernetes:1.17.4
-
cpe:2.3:a:kubernetes:kubernetes:1.17.5
-
cpe:2.3:a:kubernetes:kubernetes:1.17.6
-
cpe:2.3:a:kubernetes:kubernetes:1.17.7
-
cpe:2.3:a:kubernetes:kubernetes:1.17.8
-
cpe:2.3:a:kubernetes:kubernetes:1.17.9
-
cpe:2.3:a:kubernetes:kubernetes:1.18.0
-
cpe:2.3:a:kubernetes:kubernetes:1.18.1
-
cpe:2.3:a:kubernetes:kubernetes:1.18.2
-
cpe:2.3:a:kubernetes:kubernetes:1.18.3
-
cpe:2.3:a:kubernetes:kubernetes:1.18.4
-
cpe:2.3:a:kubernetes:kubernetes:1.18.5
-
cpe:2.3:a:kubernetes:kubernetes:1.18.6
-
cpe:2.3:a:kubernetes:kubernetes:1.18.7
-
cpe:2.3:a:kubernetes:kubernetes:1.18.8
-
cpe:2.3:a:kubernetes:kubernetes:1.18.9
-
cpe:2.3:a:kubernetes:kubernetes:1.19.0
-
cpe:2.3:a:kubernetes:kubernetes:1.19.1
-
cpe:2.3:a:kubernetes:kubernetes:1.19.2