漏洞标题
kube-audit-rest 示例日志配置可能在审计日志中泄露密钥值
漏洞描述信息
kube-audit-rest 是一款对针对 k8s api 的变更/创建请求进行简单记录的日志工具。如果在实际集群中使用了 "full-elastic-stack" 示例矢量配置,那么 Kubernetes 密钥的先前值将会在审计消息中被披露。此漏洞已在 1.0.16 版本中修复。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
漏洞类别
信息暴露
漏洞标题
kube-audit-rest's example logging configuration could disclose secret values in the audit log
漏洞描述信息
kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages. This vulnerability is fixed in 1.0.16.
CVSS信息
N/A
漏洞类别
信息暴露