PT-2026-70871 · Unknown · Insights-Client
CVE-2026-71845
·
Published
2026-08-11
·
Updated
2026-08-27
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
insights-client (affected versions not specified)
Description
A flaw exists in the
setDefault() function that logs the value of every environment variable it processes. This includes CCX TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, this token is written in clear text to the pod log during every startup. An attacker with access to pod logs or centralized logging could obtain this credential to gain unauthorized access to the CCX API.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Insights-Client