CVE-2020-8563
Red Hat Enterprise Linux CoreOS (RHCOS) vulnerability analysis and mitigation

Overview

In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This vulnerability (CVE-2020-8563) affects Kubernetes versions prior to v1.19.3. The issue was discovered and reported by Kaizhe Huang (derek0405) (Kubernetes Issue, Google Groups).

Technical details

The vulnerability occurs when the cloud-controller-manager starts and sets up an informer on the user cloud object. When the attributes 'secret-name' and 'secret-namespace' are specified in the vsphere.conf file, and the logging level is set to 4 or above, the system logs sensitive information including vSphere credentials. The vulnerability has been assigned a CVSS score of 5.6 (Medium), considering that exploitation requires privileges to access the node where the component resides (Sysdig Blog).

Impact

If exploited, the vulnerability allows anyone with access to the cloud-controller-manager's log to view the vSphere credentials. If the exposed credentials belong to a vSphere administrator (which is the most likely scenario), the entire cluster could be compromised. The severity increases to 7.7 (High) if the log level was initially set to 4 or above, as no special access would be required to view the secrets (Sysdig Blog).

Exploitability

The vulnerability can be exploited when three conditions are met: the Kubernetes cluster is built on vSphere, the logging level of cloud-controller-manager is set to 4 or above, and Kubernetes secrets are used to store the vSphere credentials. The exploit requires access to the cloud-provider-controller's log (Sysdig Blog).

Mitigation and workarounds

To mitigate this vulnerability, administrators should immediately update their vSphere passwords if potentially exposed. It's recommended to check for Kubernetes components like kube-apiserver and kube-controller-manager that may be starting with verbose logging. The vulnerability is fixed in Kubernetes version v1.19.3. Additionally, organizations should ensure that log levels are kept at their default values and access to cluster logs is strictly controlled (Sysdig Blog).

Additional resources


SourceThis report was generated using AI

Related Red Hat Enterprise Linux CoreOS (RHCOS) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68343CRITICAL9.1
  • Linux Kernel logoLinux Kernel
  • kernel-uek-modules-usb
NoYesAug 10, 2026
CVE-2026-72693HIGH7.8
  • Rocky Linux logoRocky Linux
  • kbd
NoYesAug 11, 2026
CVE-2026-16313HIGH7.6
  • Rocky Linux logoRocky Linux
  • openshift::ose-rhel-coreos-9-0:4.19.9.6.202609021231-0
NoYesJul 28, 2026
CVE-2026-14957HIGH7.5
  • Rocky Linux logoRocky Linux
  • libreswan
NoYesSep 02, 2026
CVE-2026-15816HIGH7.5
  • Rocky Linux logoRocky Linux
  • dracut.src
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management