Skip to content

x/vulndb: potential Go vuln in github.com/edgelesssys/contrast: GHSA-h5f8-crrq-4pw8 #3718

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-h5f8-crrq-4pw8 references a vulnerability in the following Go modules:

Module
github.com/edgelesssys/contrast

Description:

Impact

When the Contrast initializer is configured with a CONTRAST_LOG_LEVEL of info or debug, the workload secret is logged to stderr and written to Kubernetes logs.

Since info is the default setting, this affects all Contrast installations that don't customize their initializers' log level.

The following audiences are intended to have access to workload secrets (see https://docs.edgeless.systems/contrast/1.7/architecture/secrets#workload-secrets):

  • Contrast Coordinator (can derive all workload secrets)
  • Contrast Initializer (obtains only the secret configured in the ...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/edgelesssys/contrast
      non_go_versions:
        - introduced: TODO (earliest fixed "1.8.1", vuln range "<= 1.8.0")
      vulnerable_at: 1.8.1
summary: Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast
ghsas:
    - GHSA-h5f8-crrq-4pw8
references:
    - advisory: https://github.com/advisories/GHSA-h5f8-crrq-4pw8
    - advisory: https://github.com/edgelesssys/contrast/security/advisories/GHSA-h5f8-crrq-4pw8
source:
    id: GHSA-h5f8-crrq-4pw8
    created: 2025-05-28T15:01:36.945451612Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions