-
Notifications
You must be signed in to change notification settings - Fork 73
Closed
Labels
Description
Advisory GHSA-h5f8-crrq-4pw8 references a vulnerability in the following Go modules:
| Module |
|---|
| github.com/edgelesssys/contrast |
Description:
Impact
When the Contrast initializer is configured with a CONTRAST_LOG_LEVEL of info or debug, the workload secret is logged to stderr and written to Kubernetes logs.
Since info is the default setting, this affects all Contrast installations that don't customize their initializers' log level.
The following audiences are intended to have access to workload secrets (see https://docs.edgeless.systems/contrast/1.7/architecture/secrets#workload-secrets):
- Contrast Coordinator (can derive all workload secrets)
- Contrast Initializer (obtains only the secret configured in the ...
References:
- ADVISORY: GHSA-h5f8-crrq-4pw8
- ADVISORY: GHSA-h5f8-crrq-4pw8
Cross references:
- github.com/edgelesssys/contrast appears in 1 other report(s):
- data/reports/GO-2025-3455.yaml (x/vulndb: potential Go vuln in github.com/edgelesssys/contrast: GHSA-vqv5-385r-2hf8 #3455)
See doc/quickstart.md for instructions on how to triage this report.
id: GO-ID-PENDING
modules:
- module: github.com/edgelesssys/contrast
non_go_versions:
- introduced: TODO (earliest fixed "1.8.1", vuln range "<= 1.8.0")
vulnerable_at: 1.8.1
summary: Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast
ghsas:
- GHSA-h5f8-crrq-4pw8
references:
- advisory: https://github.com/advisories/GHSA-h5f8-crrq-4pw8
- advisory: https://github.com/edgelesssys/contrast/security/advisories/GHSA-h5f8-crrq-4pw8
source:
id: GHSA-h5f8-crrq-4pw8
created: 2025-05-28T15:01:36.945451612Z
review_status: UNREVIEWED