Kubernetes Secrets Store Sync Controller Vulnerability Affecting Service Account Tokens
CVE-2025-7445
6.5MEDIUM
Key Information:
- Vendor
Kubernetes
- Vendor
- CVE Published:
- 5 September 2025
What is CVE-2025-7445?
The Secrets Store Sync Controller for Kubernetes, prior to version 0.0.2, is susceptible to a vulnerability that exposes service account tokens in logs. This issue can lead to unintended disclosure of sensitive information, posing a risk to system integrity and confidentiality. Users are advised to upgrade to the latest version to mitigate potential security threats.
Affected Version(s)
secrets-store-sync-controller 0 < 0.0.2
secrets-store-sync-controller 0.0.2