In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, < v1.17.13.
2020-12-07T22:15:21.480
2024-11-21T05:39:02.657
Modified
CVSSv3.1: 4.7 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | kubernetes | kubernetes | < 1.17.13 | Yes |
| Application | kubernetes | kubernetes | < 1.18.10 | Yes |
| Application | kubernetes | kubernetes | < 1.19.3 | Yes |