Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9
Published Dec 7, 2020
5.5
MEDIUMCVSS 3.1
EPSS 0.52%
Description
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.
Affected products
-
- Version < 1.20.0-alpha2StatusaffectedConstraints-
- Version <= 1.17.13StatusaffectedConstraints-
- Version <= 1.18.10StatusaffectedConstraints-
- Version <= 1.19.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Kubernetes | n/a |
|
- ≥ 1.17.0 · ≤ 1.17.13
- ≥ 1.18.0 · ≤ 1.18.10
- ≥ 1.19.0 · ≤ 1.19.3
No data.
Red Hat OpenShift Container Storage 4.7.0 on RHEL-8
ocs4/rook-ceph-rhel8-operator:4.7-140.49a6fcf.release_4.7
Fixed · RHSA-2021:2041
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8
ocs4/cephcsi-rhel8:4.8-125.01872cc.release_4.8
Fixed · RHBA-2021:3003
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8
ocs4/mcg-core-rhel8:5.8.0-38.e060925.5.8
Fixed · RHBA-2021:3003
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8
ocs4/mcg-rhel8-operator:5.8.0-27.4a6ca5f.5.8
Fixed · RHBA-2021:3003
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8
ocs4/ocs-must-gather-rhel8:4.8-196.a35d7d7.release_4.8
Fixed · RHBA-2021:3003
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8
ocs4/ocs-operator-bundle:4.8.0-5
Fixed · RHBA-2021:3003
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8
ocs4/ocs-rhel8-operator:4.8-196.a35d7d7.release_4.8
Fixed · RHBA-2021:3003
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8
ocs4/rook-ceph-rhel8-operator:4.8-167.9a9db5f.release_4.8
Fixed · RHBA-2021:3003
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8
ocs4/volume-replication-rhel8-operator:4.8-20.ab575a2.release_v0.1
Fixed · RHBA-2021:3003
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
mcg-0:5.9.0-28.61dcf87.5.9.el8
Fixed · RHSA-2021:5085
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf/odf-multicluster-rhel8-operator:4.9-30.007b3d8.release_4.9
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/cephcsi-rhel8:4.9-164.57484e3.release_4.9
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/ocs-must-gather-rhel8:4.9-257.4181add.release_4.9
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/ocs-operator-bundle:4.9.0-5
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/ocs-rhel8-operator:4.9-257.4181add.release_4.9
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/odf-console-rhel8:4.9-39.0f2fa23.release_4.9
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/odf-multicluster-operator-bundle:4.9.0-5
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/odf-multicluster-rhel8-operator:4.9-30.007b3d8.release_4.9
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/odf-operator-bundle:4.9.0-5
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/odf-rhel8-operator:4.9-59.c8bbc1f.release_4.9
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/odr-cluster-operator-bundle:4.9.0-5
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/odr-hub-operator-bundle:4.9.0-5
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/odr-rhel8-operator:4.9-27.3d037cc.release_4.9
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/rook-ceph-rhel8-operator:4.9-219.c3f67c6.release_4.9
Fixed · RHSA-2021:5086
Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8
odf4/volume-replication-rhel8-operator:4.9-28.82f68db.release_4.9
Fixed · RHSA-2021:5086
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Will not fix
Red Hat OpenShift Container Platform 4
openshift
Not affected
Red Hat OpenShift Container Platform 4
openshift-clients
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-hyperkube
Not affected
Red Hat Openshift Container Storage 4
mcg
Affected
Red Hat Openshift Container Storage 4
odf4/ocs-rhel9-operator
Affected
Red Hat Storage 3
heketi
Will not fix
Red Hat Storage 3
rhgs3/rhgs-gluster-block-prov-rhel7
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Storage 4.7.0 on RHEL-8 | ocs4/rook-ceph-rhel8-operator:4.7-140.49a6fcf.release_4.7 | Fixed | RHSA-2021:2041 |
| Red Hat OpenShift Container Storage 4.8.0 on RHEL-8 | ocs4/cephcsi-rhel8:4.8-125.01872cc.release_4.8 | Fixed | RHBA-2021:3003 |
| Red Hat OpenShift Container Storage 4.8.0 on RHEL-8 | ocs4/mcg-core-rhel8:5.8.0-38.e060925.5.8 | Fixed | RHBA-2021:3003 |
| Red Hat OpenShift Container Storage 4.8.0 on RHEL-8 | ocs4/mcg-rhel8-operator:5.8.0-27.4a6ca5f.5.8 | Fixed | RHBA-2021:3003 |
| Red Hat OpenShift Container Storage 4.8.0 on RHEL-8 | ocs4/ocs-must-gather-rhel8:4.8-196.a35d7d7.release_4.8 | Fixed | RHBA-2021:3003 |
| Red Hat OpenShift Container Storage 4.8.0 on RHEL-8 | ocs4/ocs-operator-bundle:4.8.0-5 | Fixed | RHBA-2021:3003 |
| Red Hat OpenShift Container Storage 4.8.0 on RHEL-8 | ocs4/ocs-rhel8-operator:4.8-196.a35d7d7.release_4.8 | Fixed | RHBA-2021:3003 |
| Red Hat OpenShift Container Storage 4.8.0 on RHEL-8 | ocs4/rook-ceph-rhel8-operator:4.8-167.9a9db5f.release_4.8 | Fixed | RHBA-2021:3003 |
| Red Hat OpenShift Container Storage 4.8.0 on RHEL-8 | ocs4/volume-replication-rhel8-operator:4.8-20.ab575a2.release_v0.1 | Fixed | RHBA-2021:3003 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | mcg-0:5.9.0-28.61dcf87.5.9.el8 | Fixed | RHSA-2021:5085 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf/odf-multicluster-rhel8-operator:4.9-30.007b3d8.release_4.9 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/cephcsi-rhel8:4.9-164.57484e3.release_4.9 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/ocs-must-gather-rhel8:4.9-257.4181add.release_4.9 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/ocs-operator-bundle:4.9.0-5 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/ocs-rhel8-operator:4.9-257.4181add.release_4.9 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/odf-console-rhel8:4.9-39.0f2fa23.release_4.9 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/odf-multicluster-operator-bundle:4.9.0-5 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/odf-multicluster-rhel8-operator:4.9-30.007b3d8.release_4.9 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/odf-operator-bundle:4.9.0-5 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/odf-rhel8-operator:4.9-59.c8bbc1f.release_4.9 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/odr-cluster-operator-bundle:4.9.0-5 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/odr-hub-operator-bundle:4.9.0-5 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/odr-rhel8-operator:4.9-27.3d037cc.release_4.9 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/rook-ceph-rhel8-operator:4.9-219.c3f67c6.release_4.9 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Data Foundation 4.9.0 on RHEL-8 | odf4/volume-replication-rhel8-operator:4.9-28.82f68db.release_4.9 | Fixed | RHSA-2021:5086 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift-clients | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-hyperkube | Not affected | n/a |
| Red Hat Openshift Container Storage 4 | mcg | Affected | n/a |
| Red Hat Openshift Container Storage 4 | odf4/ocs-rhel9-operator | Affected | n/a |
| Red Hat Storage 3 | heketi | Will not fix | n/a |
| Red Hat Storage 3 | rhgs3/rhgs-gluster-block-prov-rhel7 | Will not fix | n/a |
k8s.io/kubernetes
Go
Introduced 0 Fixed 1.20.0-alpha.2k8s.io/client-go
Go
Introduced 0 Fixed 0.20.0-alpha.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | k8s.io/kubernetes | 0 | 1.20.0-alpha.2 |
| Go | k8s.io/client-go | 0 | 0.20.0-alpha.2 |
Remediation
Vendor solution
Do not enable verbose logging in production (log level >= 9), limit access to logs.
Red Hat statement
OpenShift Container Platform 4 does not support LogLevels higher than 8 (via 'TraceAll'), and is therefore not affected by this vulnerability.
References (15)
- https://access.redhat.com/security/cve/CVE-2020-8565 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1886638 Issue Tracking
- https://github.com/advisories/GHSA-8cfg-vx93-jvxw Advisory
- https://github.com/kubernetes/client-go/commit/19875a3d5a2e0d4f51c976a9e0662de3c2c011e3
- https://github.com/kubernetes/client-go/commit/1b8383fc150c9b816b0072032cca75754c2734d0
- https://github.com/kubernetes/client-go/commit/44e1a07f2d513e375c4b6ee6e890040b47befe86
- https://github.com/kubernetes/client-go/commit/e8f871a2e5fadf90fc114565abc0963967f1a373
- https://github.com/kubernetes/kubernetes/commit/e99df0e5a75eb6e86123b56d53e9b7ca0fd00419
- https://github.com/kubernetes/kubernetes/issues/95623 x_refsource_CONFIRMThird Party Advisory
- https://github.com/kubernetes/kubernetes/pull/95316
- https://groups.google.com/g/kubernetes-announce/c/ScdmyORnPDk
- https://groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8565
- https://pkg.go.dev/vuln/GO-2021-0064
- https://www.cve.org/CVERecord?id=CVE-2020-8565
Change history (0)
No recorded changes yet.