VDB
Sign up
MEDIUM6.5

GHSA-jmrx-5g74-6v2f

Kubernetes client-go library logs may disclose credentials to unauthorized users

Quick fix

GHSA-jmrx-5g74-6v2f — k8s.io/client-go: upgrade to the fixed version with the command below.

go get k8s.io/client-go@v0.17.0

Details

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/k8s.io/client-go
Introduced in: 0Fixed in: 0.17.0
Fixgo get k8s.io/client-go@v0.17.0
Go/k8s.io/kubernetes
Introduced in: 0Fixed in: 1.16.0-beta.1
Fixgo get k8s.io/kubernetes@v1.16.0-beta.1

References