kube-audit-rest's example logging configuration could disclose secret values in the audit log
Moderate severity
GitHub Reviewed
Published
Jan 29, 2025
in
RichardoC/kube-audit-rest
•
Updated Jan 29, 2025
Package
Affected versions
< 0.0.0-20250129191722-db1aa5b86725
Patched versions
0.0.0-20250129191722-db1aa5b86725
Description
Published to the GitHub Advisory Database
Jan 29, 2025
Reviewed
Jan 29, 2025
Published by the National Vulnerability Database
Jan 29, 2025
Last updated
Jan 29, 2025
Impact
If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages.
Patches
The example has been updated to fix this in commit db1aa5b867256b0a7bf206544c6981ab068b73dc
Workarounds
Replace
In the vector "audit-files-json-parser-and-redaction" step
with
References