QID 377847

Date Published: 2023-01-30

QID 377847: Kubernetes Ceph RBD Admin Secrets exposed Vulnerability

Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.

Affected version:
kubernetes v1.19.0 - v1.19.2
kubernetes v1.18.0 - v1.18.9
kubernetes v1.17.0 - v1.17.12
QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes

Successful exploitation of the vulnerability may allow an attacker to Ceph RBD adminSecrets exposed in logs

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    For more information please visit 95624

    Workaround:
    Vulnerable If Ceph RBD volumes are in use and kube-controller-manager is using a log level of at least 4.

    CVEs related to QID 377847

    Software Advisories
    Advisory ID Software Component Link
    95624 URL Logo github.com/kubernetes/kubernetes/issues/95624