Edgeless Systems · Contrast · CVE-2025-71425
**Name of the Vulnerable Software and Affected Versions**
Contrast (Edgeless Systems) versions prior to 1.8.1
**Description**
The Contrast initializer logs the workload secret to stderr, which directs the information into Kubernetes logs. This occurs when the `CONTRAST LOG LEVEL` variable is set to info or debug. Since info is the default setting, most installations are affected. This issue exposes workload secrets to Kubernetes users with permissions to get or list pods/logs, as well as entities with read access to the Kubernetes log storage, such as cloud providers.
**Recommendations**
Update Contrast (Edgeless Systems) to version 1.8.1 or later.
As a temporary mitigation, change the `CONTRAST LOG LEVEL` variable to a level other than info or debug.