CyberRota Analysis
AI-GeneratedKubernetes installations using Contrast (Edgeless Systems) versions prior to 1.8.1 are vulnerable due to the logging of workload secrets to stderr when the default log level is set to info or debug. This exposure allows unauthorized Kubernetes users with permissions to access pod logs to view sensitive workload secrets, posing a significant security risk. Organizations utilizing Kubernetes with Contrast should prioritize upgrading to version 1.8.1 or later to mitigate this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affected. This exposes workload secrets — normally accessible only to the Contrast Coordinator, the initializer, the seedshare owner, and the workload owner — to Kubernetes users with get or list permission on pods/logs and to anyone with read access to the Kubernetes log storage, such as the cloud provider. Deployments that do not use workload secrets are unaffected.