Back

MEDIUM

Docker config secrets leaked when file is malformed and loglevel >= 4

Published Dec 7, 2020

Description

In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.

Affected products

Remediation

Vendor solution

Do not enable verbose logging in production (log level >= 4), limit access to logs.

Metrics

Weaknesses (2)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Dec 7, 2020
Updated Sep 16, 2024
Reserved Feb 3, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 14, 2020
GHSA-8MJG-8C8G-6H85