GPU VulnDB

Database/Container, Kubernetes & orchestration

Contrast initializer: workload secrets logged to Kubernetes pod logs at the default log level

CVSS 8.5CVE-2025-71425Container, Kubernetes & orchestrationcurated

Impact

The Contrast initializer writes the workload secret to stderr, which Kubernetes captures as pod logs. Because info is the default log level, installations that never touched CONTRAST_LOG_LEVEL are affected. Workload secrets back encrypted storage and Vault integration, so anyone with get or list on pods/log - a broad, commonly granted RBAC verb - or read access to wherever the cluster ships its logs, including the cloud provider, obtains material that decrypts tenant data. On a multi-tenant GPU cluster that means a namespace-scoped tenant or an observability pipeline can read secrets the confidential-computing design intended to keep from the platform operator entirely. The record notes this issue recurred later as CVE-2025-71423 in the 1.9.0-1.12.2 range; deployments that do not use workload secrets are unaffected.

Who can reach it

Any authenticated Kubernetes principal with get or list on pods/log in the workload namespace, or anyone with read access to the cluster's log storage or the cloud provider's logging backend. No exploit, only a log read.

What to do

Upgrade Contrast to 1.8.1 or later and redeploy affected workloads so the initializer runs the fixed code. Treat every workload secret that was ever logged as compromised: rotate the secrets, re-key anything encrypted under them, rotate the Vault material they unlocked, and purge or restrict the retained pod logs and any log-aggregation copies. Rotation, not the upgrade, is the expensive part. Cost is a workload redeploy plus credential rotation; no node maintenance.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.