PT-2020-20211 · Linux Foundation+3 · Kubernetes+2

Patrick Rhomberg

·

Published

2020-10-15

·

Updated

2026-04-01

·

CVE-2020-8565

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kubernetes versions prior to v1.20.0-alpha2 Kubernetes versions 1.19.3 and earlier Kubernetes versions 1.18.10 and earlier Kubernetes versions 1.17.13 and earlier
Description In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl.
Recommendations For versions prior to v1.20.0-alpha2, consider reducing the logging level to prevent sensitive information from being written to log files. For versions 1.19.3 and earlier, update to a version later than v1.19.3 to mitigate the risk. For versions 1.18.10 and earlier, update to a version later than v1.18.10 to mitigate the risk. For versions 1.17.13 and earlier, update to a version later than v1.17.13 to mitigate the risk. As a temporary workaround, consider disabling debug-level logging until a patch is available.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1227
ALT-PU-2021-1495
ALT-PU-2022-1245
AZL-41878
CLEANSTART-2026-GI67088
CLEANSTART-2026-TC31671
CVE-2020-8565
GHSA-8CFG-VX93-JVXW
GO-2021-0064
RHSA-2021:5085
SUSE-SU-2020:3760-1

Affected Products

Alt Linux
Kubernetes
Suse