Impact
An issue in the insights‑client component causes request headers to be logged when a non‑200 response is received, and the headers may contain a cloud.openshift.com pull‑secret bearer token. This results in sensitive long‑lived credentials being recorded in pod logs, potentially exposing them to local users with access to those logs. The weakness is a Classic Information Exposure flaw (CWE‑532).
Affected Systems
The vulnerability affects Red Hat Advanced Cluster Management for Kubernetes 2, as distributed through the insights‑client package. No specific sub‑versions are listed, so any deployment of ACM 2 that utilizes this component may be impacted.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate confidentiality impact. Although the EPSS score is under 1%, implying a low probability of mass exploitation, the flaw is not listed in the CISA KEV catalog. The attack vector is local: an attacker already able to read pod logs would be able to recover the pulled‑secret and potentially gain unauthorized access to Red Hat cloud services. Without a public exploit, the risk remains largely constrained to environments where local user privileges are privileged or insecure.
OpenCVE Enrichment