CVE-2025-71423: Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure
Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list permission on pods/logs. Because workload secrets are used for encrypted storage and Vault integration, those must also be considered compromised. This is a regression of GHSA-h5f8-crrq-4pw8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Edgelesssys Contrastto a version that resolves this vulnerability.Fixed in 1.12.2
Event History
Frequently Asked Questions
Who can access the exposed workload secrets?
Any Kubernetes user with get or list permission on pods/logs can access the initializer's INFO-level output containing the full NewMeshCert response and workload secret.
What must an attacker be able to do to exploit this issue?
The attacker needs Kubernetes permission to get or list pod logs. No user interaction is required.
Which deployments are affected?
Edgelesssys Contrast versions from 1.9.0 up to, but not including, 1.12.2 are affected.
What assets should be treated as compromised if vulnerable logs were accessible?
Treat the workload secrets as compromised. Because those secrets are used for encrypted storage and Vault integration, the associated encrypted-storage and Vault integration secrets must also be considered compromised.
How can I determine whether my environment is affected?
Check whether Contrast is running a version in the affected range and inspect initializer standard-output logs for full NewMeshCert responses. Also identify Kubernetes users or identities that have get or list access to pods/logs, as they could have accessed the disclosed secrets.