Ceph RBD adminSecrets exposed in logs when loglevel >= 4
Published Dec 7, 2020
5.5
MEDIUMCVSS 3.1
EPSS 0.53%
Description
In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, < v1.17.13.
Affected products
-
- Version < 1.17.13StatusaffectedConstraints-
- Version < 1.18.10StatusaffectedConstraints-
- Version < 1.19.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Kubernetes | n/a |
|
- ≥ 1.17.0 · < 1.17.13
- ≥ 1.18.0 · < 1.18.10
- ≥ 1.19.0 · < 1.19.3
No data.
Red Hat OpenShift Container Platform 4.6
openshift4/ose-hyperkube:v4.6.0-202101090040.p0
Fixed · RHSA-2021:0037
Red Hat OpenShift Container Platform 4.7
openshift-0:4.7.0-202102060108.p0.git.97095.7271b90.el7
Fixed · RHSA-2020:5634
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Will not fix
Red Hat Storage 3
heketi
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4.6 | openshift4/ose-hyperkube:v4.6.0-202101090040.p0 | Fixed | RHSA-2021:0037 |
| Red Hat OpenShift Container Platform 4.7 | openshift-0:4.7.0-202102060108.p0.git.97095.7271b90.el7 | Fixed | RHSA-2020:5634 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Will not fix | n/a |
| Red Hat Storage 3 | heketi | Not affected | n/a |
github.com/kubernetes/kubernetes
Go
Introduced 0 Fixed 1.17.13github.com/kubernetes/kubernetes
Go
Introduced 1.18.0 Fixed 1.18.10github.com/kubernetes/kubernetes
Go
Introduced 1.19.0 Fixed 1.19.3k8s.io/kubernetes
Go
Introduced 1.18.0 Fixed 1.18.10k8s.io/kubernetes
Go
Introduced 1.19.0 Fixed 1.19.3k8s.io/kubernetes
Go
Introduced 0 Fixed 1.17.13
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/kubernetes/kubernetes | 0 | 1.17.13 |
| Go | github.com/kubernetes/kubernetes | 1.18.0 | 1.18.10 |
| Go | github.com/kubernetes/kubernetes | 1.19.0 | 1.19.3 |
| Go | k8s.io/kubernetes | 1.18.0 | 1.18.10 |
| Go | k8s.io/kubernetes | 1.19.0 | 1.19.3 |
| Go | k8s.io/kubernetes | 0 | 1.17.13 |
Remediation
Vendor solution
Do not enable verbose logging in production (log level >= 4), limit access to logs.
Red Hat statement
OpenShift Container Platform 4 does not support Ceph RBD persistent volumes, however the vulnerable code is included.
Red Hat mitigation
OCP Clusters not using Ceph RBD volumes are not vulnerable to this issue. For clusters using Ceph RBD volumes, this can be mitigated by ensuring the logging level is below 4 and protecting unauthorized access to cluster logs. For OCP, the logging level for core components can be configured using operators, e.g. for kube-controller-manager: https://docs.openshift.com/container-platform/latest/rest_api/operator_apis/kubecontrollermanager-operator-openshift-io-v1.html#specification In OCP, a logging level of "Debug" is equivalent to 4: https://github.com/openshift/api/blob/master/operator/v1/types.go#L96 The default logging level is "Normal", which is equivalent to 2. Clusters running with the default level are not vulnerable to this issue.
References (12)
- https://access.redhat.com/security/cve/CVE-2020-8566 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1886640 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1109 Advisory
- https://github.com/advisories/GHSA-5x96-j797-5qqw Advisory
- https://github.com/kubernetes/kubernetes/issues/95624 x_refsource_CONFIRMThird Party Advisory
- https://github.com/kubernetes/kubernetes/pull/95245
- https://github.com/kubernetes/kubernetes/pull/95245/commits/e91ec4fad3366d2dee020919f7c2a0d7b52fd3ea
- https://groups.google.com/g/kubernetes-announce/c/ScdmyORnPDk
- https://groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8566
- https://security.netapp.com/advisory/ntap-20210122-0006 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8566
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-8566 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1886640 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1109 | Advisory | |
| https://github.com/advisories/GHSA-5x96-j797-5qqw | Advisory | |
| https://github.com/kubernetes/kubernetes/issues/95624 | x_refsource_CONFIRMThird Party Advisory | |
| https://github.com/kubernetes/kubernetes/pull/95245 | ||
| https://github.com/kubernetes/kubernetes/pull/95245/commits/e91ec4fad3366d2dee020919f7c2a0d7b52fd3ea | ||
| https://groups.google.com/g/kubernetes-announce/c/ScdmyORnPDk | ||
| https://groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ | mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-8566 | ||
| https://security.netapp.com/advisory/ntap-20210122-0006 | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-8566 |
Change history (0)
No recorded changes yet.