QID 377847
Date Published: 2023-01-30
QID 377847: Kubernetes Ceph RBD Admin Secrets exposed Vulnerability
Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.
Affected version:
kubernetes v1.19.0 - v1.19.2
kubernetes v1.18.0 - v1.18.9
kubernetes v1.17.0 - v1.17.12
QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes
Successful exploitation of the vulnerability may allow an attacker to Ceph RBD adminSecrets exposed in logs
Solution
For more information please visit 95624
Workaround:
Vulnerable If Ceph RBD volumes are in use and kube-controller-manager is using a log level of at least 4.
Vendor References
CVEs related to QID 377847
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 95624 |
|