Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-27A40FCBA37CE98A22A6F81B1B92BA00
HistoryFeb 06, 2023 - 12:00 a.m.

Insertion of Sensitive Information into Log File

2023-02-0600:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
18
kubernetes
logging
security
docker
config
file
leak
pull secrets
registry
credentials
v1.19.3
v1.18.10
v1.17.13

0.0005 Low

EPSS

Percentile

17.4%

In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.

CPENameOperatorVersion
go/k8s.io/kuberneteslt1.20.0-alpha.1

0.0005 Low

EPSS

Percentile

17.4%