CVE-2020-8564: Kubernetes
Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.
Affected products
- Kubernetes Kubernetes: from 1.17.0, before 1.17.13 (fixed in 1.17.13); from 1.18.0, before 1.18.10 (fixed in 1.18.10); from 1.19.0, before 1.19.3 (fixed in 1.19.3)
Published 2020-12-07. Last modified 2026-06-17.