Description
Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.
Problem types
CWE-532 Insertion of Sensitive Information into Log File
Product status
Any version before 0.0.2
0.0.2
Credits
Reem Rotenberg
Kas Dekel
References
github.com/kubernetes/kubernetes/issues/133897
groups.google.com/...ernetes-security-announce/c/NP7cQvQ1aGA