VDB
GO-2024-2755
GO-2024-2755
PUBLISHED
CVSS 8.699999809265137 HIGH
Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes
Risk Scores
CVSS v4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| k8s.io | kubernetes | 0, 0 |
Timeline
- Jun 5, 2024 CVE Published
- Mar 3, 2026 CVE Updated
References
- https://github.com/advisories/GHSA-5xfg-wv98-264m advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1886635 url
- https://groups.google.com/g/kubernetes-announce/c/ScdmyORnPDk url
- https://groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ url
- https://security.netapp.com/advisory/ntap-20210122-0006 url
- https://github.com/kubernetes/kubernetes/issues/95621 discussion
- https://github.com/kubernetes/kubernetes/pull/95236 fix
- https://github.com/kubernetes/kubernetes/pull/95236/commits/247f6dd09299bc7893c1e0affea11c0255025b96 fix