In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/kubernetes/kubernetes(Go) | 1.19.0 | 1.19.3 | N/A |
| github.com/kubernetes/kubernetes(Go) | 1.18.0 | 1.18.10 | N/A |
| github.com/kubernetes/kubernetes(Go) | 0 | 1.17.13 | N/A |
| k8s.io/kubernetes(Go) | 0 | 1.20.0-alpha.1 | N/A |
CVSS Metrics