CVE-2020-8561 - kube-apiserver - Arch Linux


Group Package Affected Fixed Severity Status Ticket
AVG-2394 kube-apiserver 1.23.0-1 Medium Vulnerable
References
https://github.com/kubernetes/kubernetes/issues/104720
Notes
Workaround
==========

This issue can be mitigated by not allowing kube-apiserver access to sensitive resources or networks, or to reduce the “-v” flag value to less than 10 and set the “--profiling” flag value to “false” (default value is “true”). Setting the profiling flag to “false” prevents users from dynamically modifying the kube-apiserver log level, and the flag value Webhook requests may still be redirected to private networks with a log level less than 10, but the response body will not be logged.