Executive brief
Contrast, a confidential computing platform for Kubernetes, logs sensitive workload secrets to standard error and thus Kubernetes logs by default. This exposes cryptographic secrets to anyone with permission to read pod logs in Kubernetes, or to cloud providers with access to log storage. Organizations using Contrast with workload secrets are at risk unless they explicitly configure a higher log level.
Technical details
The Contrast initializer writes workload secrets to stderr when CONTRAST_LOG_LEVEL is set to "info" (the default) or "debug". Kubernetes automatically captures container stderr as logs, exposing secrets to users with pods/logs get or list RBAC permissions and to infrastructure operators. The vulnerability affects all default Contrast installations; only deployments that disable workload secrets or explicitly raise the log level are unaffected.
Affected products
- Edgeless Systems Contrast before 1.8.1
Timeline
- 2025-05-27: disclosed
- 2025-05-27: patched: Version 1.8.1 released
- 2025-09-27: advisory