Home
MEDIUM: 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:NDefault status
unaffected
Any version before 0.0.2
affected
0.0.2
unaffected
Description
Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.
Problem types
CWE-532 Insertion of Sensitive Information into Log File
Product status
Any version before 0.0.2
0.0.2
Credits
Reem Rotenberg
Kas Dekel
References
github.com/kubernetes/kubernetes/issues/133897
groups.google.com/...ernetes-security-announce/c/NP7cQvQ1aGA