QID 377852

Date Published: 2023-01-04

QID 377852: Kubernetes Docker Config Secrets Leaked Vulnerability

Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.

Affected version:
kubernetes v1.19.0 - v1.19.2
kubernetes v1.18.0 - v1.18.9
kubernetes v1.17.0 - v1.17.12
QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes

Successful exploitation of the vulnerability may allow an attacker to read docker config files

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    For more information please visit 95622

    CVEs related to QID 377852

    Software Advisories
    Advisory ID Software Component Link
    95622 URL Logo github.com/kubernetes/kubernetes/issues/95622