PT-2026-99446 · Edgeless Systems · Contrast
CVSS v4.0
8.5
High
| Vector | AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Contrast (Edgeless Systems) versions prior to 1.8.1
Description
The Contrast initializer logs the workload secret to stderr, which directs the information into Kubernetes logs. This occurs when the
CONTRAST LOG LEVEL variable is set to info or debug. Since info is the default setting, most installations are affected. This issue exposes workload secrets to Kubernetes users with permissions to get or list pods/logs, as well as entities with read access to the Kubernetes log storage, such as cloud providers.Recommendations
Update Contrast (Edgeless Systems) to version 1.8.1 or later.
As a temporary mitigation, change the
CONTRAST LOG LEVEL variable to a level other than info or debug.Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contrast