PT-2026-99444 · Edgelesssys · Contrast
CVSS v4.0
8.5
High
| Vector | AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Edgelesssys Contrast versions 1.9.0 through 1.12.1
Description
The initializer logs the full NewMeshCert response to standard output at the INFO level. This response contains the workload secret, making it accessible to any Kubernetes user with permissions to get or list pod logs. Since these workload secrets are utilized for Vault integration and encrypted storage, these components are also considered compromised.
Recommendations
Update Edgelesssys Contrast to version 1.12.2 or later.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contrast