Back

MEDIUM

Ceph RBD adminSecrets exposed in logs when loglevel >= 4

Published Dec 7, 2020

Description

In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, < v1.17.13.

Affected products

Remediation

Vendor solution

Do not enable verbose logging in production (log level >= 4), limit access to logs.

Red Hat statement

OpenShift Container Platform 4 does not support Ceph RBD persistent volumes, however the vulnerable code is included.

Red Hat mitigation

OCP Clusters not using Ceph RBD volumes are not vulnerable to this issue. For clusters using Ceph RBD volumes, this can be mitigated by ensuring the logging level is below 4 and protecting unauthorized access to cluster logs. For OCP, the logging level for core components can be configured using operators, e.g. for kube-controller-manager: https://docs.openshift.com/container-platform/latest/rest_api/operator_apis/kubecontrollermanager-operator-openshift-io-v1.html#specification In OCP, a logging level of "Debug" is equivalent to 4: https://github.com/openshift/api/blob/master/operator/v1/types.go#L96 The default logging level is "Normal", which is equivalent to 2. Clusters running with the default level are not vulnerable to this issue.

Weaknesses (2)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Dec 7, 2020
Updated Sep 16, 2024
Reserved Feb 3, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 14, 2020
ENISA EUVD
Assigner kubernetes
Published Dec 7, 2020
Updated Sep 16, 2024
Exploited since n/a
EUVD-2024-1109 GHSA-5X96-J797-5QQW