Database/Container, Kubernetes & orchestration
secrets-store-sync-controller: Service account tokens disclosed in controller logs
CVSS 6.5CVE-2025-7445Container, Kubernetes & orchestrationcurated
Impact
Service account tokens disclosed in controller logs
Who can reach it
Anyone with log-pipeline read access
What to do
Controller rollout, no GPU drain; rotate exposed tokens; scrub logs
References
Related entries
- KubeVirt: virt-handler notify server derives VMI identity from the request body without validating the connectionCVE-2026-13208 · KubeVirtMedium
- kubectl cp on Windows: a malicious in-container tar writes files to arbitrary local pathsCVE-2026-19444 · Kubernetes kubectl (kubectl cp on Windows clients)Medium
- ingress-nginx: Admission controller denial of serviceCVE-2026-24514 · ingress-nginxMedium
- CSI Driver NFS: Path traversal via `subDir` lets a tenant delete unintended directories on the shared NFS serverCVE-2026-3864 · CSI Driver NFSMedium
- CSI Driver SMB: Same `subDir` path traversal against a shared SMB serverCVE-2026-3865 · CSI Driver SMBMedium
- Contour: fallback certificate with JWT providers lets SNI-less requests skip JWT verificationCVE-2026-50149 · Projectcontour Contour ingress controller (HTTPProxy fallback certificate + jwtProviders)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.