CVE-2025-71425
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affected. This exposes workload secrets — normally accessible only to the Contrast Coordinator, the initializer, the seedshare owner, and the workload owner — to Kubernetes users with get or list permission on pods/logs and to anyone with read access to the Kubernetes log storage, such as the cloud provider. Deployments that do not use workload secrets are unaffected.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| edgelesssys | contrast | 0 < 1.8.1 | affected |
| edgelesssys | contrast | 1.8.1 | unaffected |
Weaknesses
- CWE-532: Insertion of Sensitive Information into Log File
References
- https://github.com/edgelesssys/contrast/security/advisories/GHSA-h5f8-crrq-4pw8
- https://www.vulncheck.com/advisories/contrast-before-1.8.1-information-disclosure-via-logging
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.