Impact
Contrast before version 1.8.1 logs workload secrets to standard error when the log level is set to info or debug, causing those secrets to be captured in Kubernetes pod logs. The exposure allows any user with get or list permissions on pod logs to read secrets that should be restricted to the Contrast Coordinator, initializer, seedshare owner, or workload owner. This is a direct disclosure of confidential data and is classified as CWE-532.
Affected Systems
All installations of Edgeless Systems Contrast running a version earlier than 1.8.1 and using the default log level (info) are affected. Deployments that use workload secrets are at risk; systems that do not use workload secrets are unaffected.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity vulnerability, but the EPSS score is not available, so the likelihood of exploitation is unknown. The issue appears to be exploitable via normal Kubernetes log access, meaning any authenticated Kubernetes user with pod log permissions or any cloud provider with read access to the log storage can potentially read the leaked secrets. The vulnerability is not currently listed in CISA's KEV catalog but still poses a significant confidentiality risk if the logs are accessed by an unauthorized party.
OpenCVE Enrichment