
Cloud Vulnerability DB
A community-led vulnerabilities database
In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This vulnerability (CVE-2020-8563) affects Kubernetes versions prior to v1.19.3. The issue was discovered and reported by Kaizhe Huang (derek0405) (Kubernetes Issue, Google Groups).
The vulnerability occurs when the cloud-controller-manager starts and sets up an informer on the user cloud object. When the attributes 'secret-name' and 'secret-namespace' are specified in the vsphere.conf file, and the logging level is set to 4 or above, the system logs sensitive information including vSphere credentials. The vulnerability has been assigned a CVSS score of 5.6 (Medium), considering that exploitation requires privileges to access the node where the component resides (Sysdig Blog).
If exploited, the vulnerability allows anyone with access to the cloud-controller-manager's log to view the vSphere credentials. If the exposed credentials belong to a vSphere administrator (which is the most likely scenario), the entire cluster could be compromised. The severity increases to 7.7 (High) if the log level was initially set to 4 or above, as no special access would be required to view the secrets (Sysdig Blog).
The vulnerability can be exploited when three conditions are met: the Kubernetes cluster is built on vSphere, the logging level of cloud-controller-manager is set to 4 or above, and Kubernetes secrets are used to store the vSphere credentials. The exploit requires access to the cloud-provider-controller's log (Sysdig Blog).
To mitigate this vulnerability, administrators should immediately update their vSphere passwords if potentially exposed. It's recommended to check for Kubernetes components like kube-apiserver and kube-controller-manager that may be starting with verbose logging. The vulnerability is fixed in Kubernetes version v1.19.3. Additionally, organizations should ensure that log levels are kept at their default values and access to cluster logs is strictly controlled (Sysdig Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."