GPU VulnDB

Database/Container, Kubernetes & orchestration

Contrast initializer: regression re-exposes workload secrets by logging the full NewMeshCert response

CVSS 8.5CVE-2025-71423Container, Kubernetes & orchestrationcurated

Impact

In Contrast 1.9.0 through 1.12.2 the initializer logs the entire NewMeshCert response at INFO, and that response carries the workload secret - a regression of the earlier fix tracked as GHSA-h5f8-crrq-4pw8 (see the related entry for CVE-2025-71425). Any Kubernetes user with get or list on pods/log reads the secret straight out of the log stream, and because workload secrets are used for encrypted storage and Vault integration, everything derived from them must be considered compromised too. Kept separate from the earlier issue because the affected version range and the logging site differ: an operator who patched once still needs to check whether they landed in the reintroduced window.

Who can reach it

Any authenticated Kubernetes principal with get or list on pods/log for the namespace running the initializer, plus anyone able to read the cluster's shipped logs. Requires low privilege, no exploitation.

What to do

Upgrade to Contrast 1.12.2 or later and redeploy the workloads so the initializer stops emitting the secret. Then rotate every workload secret exposed while an affected version ran, re-key encrypted storage and the Vault integration behind it, and purge the pod logs and downstream log copies that captured it. Workload redeploy plus secret rotation; no node drain or reboot.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.