CVE-2025-71425 Details
Description
Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affected. This exposes workload secrets — normally accessible only to the Contrast Coordinator, the initializer, the seedshare owner, and the workload owner — to Kubernetes users with get or list permission on pods/logs and to anyone with read access to the Kubernetes log storage, such as the cloud provider. Deployments that do not use workload secrets are unaffected.
A vulnerability in Contrast (Edgeless Systems) versions prior to 1.8.1 allows workload secrets to be logged to stderr and subsequently to Kubernetes logs. This occurs when the Contrast initializer's log level is set to info or debug, with info being the default. As a result, all installations that do not modify the initializer log level are affected. The exposed workload secrets, typically accessible only to the Contrast Coordinator, the initializer, the seedshare owner, and the workload owner, are exposed to Kubernetes users with get or list permissions on pods/logs, as well as to anyone with read access to Kubernetes log storage, such as through the cloud provider. Deployments that do not utilize workload secrets are not impacted.
To address this vulnerability, add an environment variable `CONTRAST_LOG_LEVEL=warn` to the initializer after running `contrast generate`, and then run `contrast generate` again.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Edgeless Systems Contrast | <= 1.8.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion