MEDIUM4.7
GHSA-8cfg-vx93-jvxw
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
Quick fix
GHSA-8cfg-vx93-jvxw — k8s.io/client-go: upgrade to the fixed version with the command below.
go get k8s.io/client-go@v0.19.6Details
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.5, <= v1.18.13, <= v1.17.15, < v1.20.0-alpha2.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/k8s.io/client-go
Introduced in:
0.20.0-alpha.0Fixed in: 0.20.0-alpha.2Fix
go get k8s.io/client-go@v0.20.0-alpha.2Go/k8s.io/kubernetes
Introduced in:
0Fixed in: 1.20.0-alpha.2Fix
go get k8s.io/kubernetes@v1.20.0-alpha.2References
- https://nvd.nist.gov/vuln/detail/CVE-2020-8565[ADVISORY]
- https://github.com/kubernetes/kubernetes/issues/95623[WEB]
- https://github.com/kubernetes/kubernetes/pull/95316[WEB]
- https://github.com/kubernetes/client-go/commit/19875a3d5a2e0d4f51c976a9e0662de3c2c011e3[WEB]
- https://github.com/kubernetes/client-go/commit/1b8383fc150c9b816b0072032cca75754c2734d0[WEB]
- https://github.com/kubernetes/client-go/commit/44e1a07f2d513e375c4b6ee6e890040b47befe86[WEB]
- https://github.com/kubernetes/client-go/commit/e8f871a2e5fadf90fc114565abc0963967f1a373[WEB]
- https://github.com/kubernetes/kubernetes/commit/e99df0e5a75eb6e86123b56d53e9b7ca0fd00419[WEB]
- https://github.com/kubernetes/client-go[PACKAGE]
- https://groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ[WEB]
- https://pkg.go.dev/vuln/GO-2021-0064[WEB]