Information Disclosure Vulnerability in Contrast by Edgeless Systems
CVE-2025-71425
8.5HIGH
What is CVE-2025-71425?
The Contrast product prior to version 1.8.1 has a vulnerability where workload secrets are logged to stderr when the Contrast initializer is set to log levels of info or debug. This poses a significant risk as it allows unauthorized Kubernetes users with permission to access pod logs to view sensitive information typically restricted to specific roles. Administrators who do not adjust the default log level settings may inadvertently expose these secrets, leading to potential breaches and unauthorized access to critical workload data.
Affected Version(s)
contrast 0 < 1.8.1
contrast 1.8.1
