{"schema_version":"1.7.3","id":"GHSA-8cfg-vx93-jvxw","published":"2023-02-06T23:27:56Z","modified":"2026-02-04T03:21:08.320563Z","aliases":["CVE-2020-8565","GO-2021-0064"],"related":["CGA-r5j8-36p9-q5pc"],"summary":"Kubernetes client-go vulnerable to Sensitive Information Leak via Log File","details":"In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.5, <= v1.18.13, <= v1.17.15, < v1.20.0-alpha2.","affected":[{"package":{"name":"k8s.io/client-go","ecosystem":"Go","purl":"pkg:golang/k8s.io/client-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.19.0"},{"fixed":"0.19.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-8cfg-vx93-jvxw/GHSA-8cfg-vx93-jvxw.json"}},{"package":{"name":"k8s.io/client-go","ecosystem":"Go","purl":"pkg:golang/k8s.io/client-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.20.0-alpha.0"},{"fixed":"0.20.0-alpha.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-8cfg-vx93-jvxw/GHSA-8cfg-vx93-jvxw.json"}},{"package":{"name":"k8s.io/client-go","ecosystem":"Go","purl":"pkg:golang/k8s.io/client-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.18.0"},{"fixed":"0.18.14"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-8cfg-vx93-jvxw/GHSA-8cfg-vx93-jvxw.json"}},{"package":{"name":"k8s.io/client-go","ecosystem":"Go","purl":"pkg:golang/k8s.io/client-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.17.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-8cfg-vx93-jvxw/GHSA-8cfg-vx93-jvxw.json"}},{"package":{"name":"k8s.io/kubernetes","ecosystem":"Go","purl":"pkg:golang/k8s.io/kubernetes"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.20.0-alpha.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-8cfg-vx93-jvxw/GHSA-8cfg-vx93-jvxw.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-8565"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/issues/95623"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/pull/95316"},{"type":"WEB","url":"https://github.com/kubernetes/client-go/commit/19875a3d5a2e0d4f51c976a9e0662de3c2c011e3"},{"type":"WEB","url":"https://github.com/kubernetes/client-go/commit/1b8383fc150c9b816b0072032cca75754c2734d0"},{"type":"WEB","url":"https://github.com/kubernetes/client-go/commit/44e1a07f2d513e375c4b6ee6e890040b47befe86"},{"type":"WEB","url":"https://github.com/kubernetes/client-go/commit/e8f871a2e5fadf90fc114565abc0963967f1a373"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/commit/e99df0e5a75eb6e86123b56d53e9b7ca0fd00419"},{"type":"PACKAGE","url":"https://github.com/kubernetes/client-go"},{"type":"WEB","url":"https://groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2021-0064"}],"database_specific":{"cwe_ids":["CWE-532"],"github_reviewed":true,"github_reviewed_at":"2023-02-06T23:27:56Z","nvd_published_at":null,"severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}