vulnerability

Kubernetes: CVE-2020-8563: Secret leaks in kube-controller-manager when using vSphere provider

Severity
2
CVSS
(AV:L/AC:L/Au:N/C:P/I:N/A:N)
Published
2020-12-07
Added
2020-12-21
Modified
2024-11-19

Description

In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects

Solution

kubernetes-upgrade-1_19_3
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.