kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages. This vulnerability is fixed in 1.0.16.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 29 Jan 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages. This vulnerability is fixed in 1.0.16. | |
Title | kube-audit-rest's example logging configuration could disclose secret values in the audit log | |
Weaknesses | CWE-200 CWE-212 CWE-532 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-31T16:56:01.134Z
Reserved: 2025-01-27T15:32:29.450Z
Link: CVE-2025-24884

Updated: 2025-01-31T16:55:56.382Z

Status : Received
Published: 2025-01-29T21:15:21.667
Modified: 2025-01-29T21:15:21.667
Link: CVE-2025-24884

No data.