Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-AE2D23095470B73558795A81776A9FCD
HistoryFeb 06, 2023 - 12:00 a.m.

Insertion of Sensitive Information into Log File

2023-02-0600:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
12
kubernetes
logging level
authorization
bearer tokens
api server
client tool
v1.19.3
v1.18.10
v1.17.13
v1.20.0-alpha2

0.0004 Low

EPSS

Percentile

12.7%

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

CPENameOperatorVersion
go/k8s.io/client-golt0.20.0-alpha.2