This repository has been archived by the owner on Sep 22, 2024. It is now read-only.
CVE-2020-8564 (Medium) detected in github.com/google/go-containerregistry-v0.1.0 - autoclosed #14
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2020-8564 - Medium Severity Vulnerability
Vulnerable Library - github.com/google/go-containerregistry-v0.1.0
Go library and CLIs for working with container registries
Dependency Hierarchy:
Found in HEAD commit: e49e2f33b77657ce4ab7eac9abebafc4a1fd18ba
Found in base branch: master
Vulnerability Details
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.
Publish Date: 2020-12-07
URL: CVE-2020-8564
CVSS 3 Score Details (5.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: kubernetes/kubernetes#95622
Release Date: 2020-12-07
Fix Resolution: v1.17.13,v1.18.10,v1.19.3
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: