QID 377848
Date Published: 2023-01-04
QID 377848: Kubernetes Token Leak Logs Vulnerability
Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.
Affected version:
kubernetes v1.19.0 - v1.19.5
kubernetes v1.18.0 - v1.18.13
kubernetes v1.17.0 - v1.17.15
QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes
Successful exploitation of the vulnerability may allow an attacker authorization and bearer tokens will be written to log files
Solution
For more information please visit 95623
Workaround:
Vulnerable If kube-apiserver is using a log level of at least 9.
Vendor References
CVEs related to QID 377848
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 95623 |
|