CVE-2025-24884

kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages. This vulnerability is fixed in 1.0.16.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) kube-audit-rest es un registrador simple de solicitudes de mutación/creación a la API de k8s. Si se hubiera utilizado la configuración de vector de ejemplo "full-elastic-stack" para un clúster real, los valores anteriores de los secretos de Kubernetes se habrían revelado en los mensajes de auditoría. Esta vulnerabilidad se solucionó en la versión 1.0.16.

29 Jan 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-29 21:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-24884

Mitre link : CVE-2025-24884

CVE.ORG link : CVE-2025-24884


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer

CWE-532

Insertion of Sensitive Information into Log File