VDB
Sign up
MEDIUM4.7

GHSA-8cfg-vx93-jvxw

Kubernetes client-go vulnerable to Sensitive Information Leak via Log File

Quick fix

GHSA-8cfg-vx93-jvxw — k8s.io/client-go: upgrade to the fixed version with the command below.

go get k8s.io/client-go@v0.19.6

Details

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.5, <= v1.18.13, <= v1.17.15, < v1.20.0-alpha2.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/k8s.io/client-go
Introduced in: 0.19.0Fixed in: 0.19.6
Fixgo get k8s.io/client-go@v0.19.6
Go/k8s.io/client-go
Introduced in: 0.20.0-alpha.0Fixed in: 0.20.0-alpha.2
Fixgo get k8s.io/client-go@v0.20.0-alpha.2
Go/k8s.io/client-go
Introduced in: 0.18.0Fixed in: 0.18.14
Fixgo get k8s.io/client-go@v0.18.14
Go/k8s.io/client-go
Introduced in: 0Fixed in: 0.17.16
Fixgo get k8s.io/client-go@v0.17.16
Go/k8s.io/kubernetes
Introduced in: 0Fixed in: 1.20.0-alpha.2
Fixgo get k8s.io/kubernetes@v1.20.0-alpha.2

References