Sceawere

Vulnerability Detail

CVE-2025-71423UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Edgelesssys Contrast Secret Exposure Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
1d ago
Vendor
edgelesssys
Product
contrast
Attack Type
Insertion of Sensitive Information into Log File
Vector String
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list permission on pods/logs. Because workload secrets are used for encrypted storage and Vault integration, those must also be considered compromised. This is a regression of GHSA-h5f8-crrq-4pw8.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-27T02:17:15.993Z",
  "pubdate": "2026-09-27T02:17:15.993Z",
  "executiveSummary": "The Edgelesssys Contrast confidential-computing runtime contains a critical information disclosure vulnerability caused by improper logging practices. In affected versions, the initialization process logs the full NewMeshCert response, which inherently includes sensitive workload secrets, to the standard output stream at the INFO log level.\nThis vulnerability exposes high-value cryptographic material and workload secrets to any entity with read access to Kubernetes pod logs. Because these secrets are foundational for encrypted storage and HashiCorp Vault integrations, their compromise leads to a total breach of the workload's security posture.\nThe flaw affects Edgelesssys Contrast versions 1.9.0 through 1.12.1 and represents a functional regression of the previously addressed GHSA-h5f8-crrq-4pw8. The risk is considered high, as an attacker with standard Kubernetes RBAC permissions—specifically those granted 'get' or 'list' access to pod logs—can harvest these secrets without direct interaction with the workload container. Successful exploitation allows for the decryption of protected storage, unauthorized access to secret management systems, and complete compromise of confidential computing guarantees.\nOrganizations using the affected software are at risk of lateral movement and data exfiltration within their Kubernetes clusters due to the exposure of identity and encryption material.",
  "technicalDetails": "The root cause of this vulnerability is the insecure implementation of the initialization routine within the Contrast runtime, where the full NewMeshCert API response object is passed to the logging subsystem. By defaulting to the INFO log level, the application systematically writes the entire contents of this response—including private workload secrets—to the standard output (stdout) of the container. In a Kubernetes environment, these logs are captured by the container runtime and made available to the control plane, where they can be queried via the Kubernetes API.\nThe attack flow proceeds as follows: 1) The attacker gains or leverages existing Kubernetes RBAC permissions that permit the execution of 'get' or 'list' operations on pod resources and their associated logs. 2) The attacker identifies a target pod running a vulnerable version of Edgelesssys Contrast. 3) The attacker issues a command such as 'kubectl logs' against the target pod. 4) The API server returns the log stream containing the plaintext secrets emitted by the initializer. 5) The attacker parses the logs to extract the NewMeshCert response data.\nThe vulnerable component is the Contrast runtime initializer, which fails to scrub or redact sensitive fields before outputting telemetry. This exposure circumvents the memory-isolation protections intended by confidential computing, as the secrets are persisted in plaintext within the observability layer of the host orchestrator. Because these secrets are utilized for downstream security operations, including the orchestration of encrypted storage volumes and the authentication tokens for Vault integrations, the compromise is catastrophic. The impact extends beyond the runtime itself, effectively nullifying the trust boundary between the confidential workload and the Kubernetes control plane. Post-exploitation, an attacker can utilize the harvested secrets to impersonate the workload, decrypt persistent storage volumes, or gain unauthorized access to credentials stored within HashiCorp Vault, leading to further privilege escalation or data breaches within the infrastructure.\nAffected versions are strictly defined as 1.9.0 up to, but not including, 1.12.2. The vulnerability is characterized as a regression, implying that prior security controls aimed at preventing secret logging were inadvertently removed or bypassed in the affected release cycle."
}
CVE-2025-71423: Edgelesssys Contrast Secret Exposure Vulnerability (HIGH Severity, CVSS: 7.3) | Sceawere