Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.
Workaround:
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://github.com/kubernetes/kubernetes/issues/118419 | issue tracking exploit |
https://groups.google.com/g/kubernetes-security-announce/c/5K8ghQHBDdQ/m/Udee6YUgAAAJ | mailing list |
https://security.netapp.com/advisory/ntap-20230814-0003/ | third party advisory |