CVE-2025-24884

MEDIUM

kube-audit-rest <1.0.16 - Info Disclosure

Title source: llm
STIX 2.1

Description

kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages. This vulnerability is fixed in 1.0.16.

Scores

CVSS v4 5.1
EPSS 0.0005
EPSS Percentile 14.8%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-212 CWE-532
Status published
Products (2)
RichardoC/kube-audit-rest 0 - 0.0.0-20250205113217-9df8886b4819Go
RichardoC/kube-audit-rest < 1.0.16
Published Jan 29, 2025
Tracked Since Feb 18, 2026