From 99a0781c7ae32afb19ebd90c226724dfd5c13822 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 5 Feb 2025 16:30:14 +0000 Subject: [PATCH] Publish GHSA-hcr5-wv4p-h2g2 --- .../01/GHSA-hcr5-wv4p-h2g2/GHSA-hcr5-wv4p-h2g2.json | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2025/01/GHSA-hcr5-wv4p-h2g2/GHSA-hcr5-wv4p-h2g2.json b/advisories/github-reviewed/2025/01/GHSA-hcr5-wv4p-h2g2/GHSA-hcr5-wv4p-h2g2.json index e1111b1821f..66f64a5ed5b 100644 --- a/advisories/github-reviewed/2025/01/GHSA-hcr5-wv4p-h2g2/GHSA-hcr5-wv4p-h2g2.json +++ b/advisories/github-reviewed/2025/01/GHSA-hcr5-wv4p-h2g2/GHSA-hcr5-wv4p-h2g2.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-hcr5-wv4p-h2g2", - "modified": "2025-01-29T22:00:39Z", + "modified": "2025-02-05T16:28:49Z", "published": "2025-01-29T20:47:51Z", "aliases": [ "CVE-2025-24884" ], "summary": "kube-audit-rest's example logging configuration could disclose secret values in the audit log", - "details": "### Impact\nIf the \"full-elastic-stack\" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages.\n\n### Patches\nThe example has been updated to fix this in commit db1aa5b867256b0a7bf206544c6981ab068b73dc\n\n\n### Workarounds\nReplace \n```yaml\n\n if .request.requestKind.kind == \"Secret\" {\n del(.request.object.data)\n .request.object.data.redacted = \"REDACTED\"\n del(.request.oldObject.data)\n .request.oldObject.data.redacted = \"REDACTED\"\n }\n```\nIn the vector \"audit-files-json-parser-and-redaction\" step\nwith\n```yaml\n\n if .request.requestKind.kind == \"Secret\" {\n # Redact the secret data\n del(.request.object.data)\n .request.object.data.redacted = \"REDACTED\"\n del(.request.oldObject.data)\n .request.oldObject.data.redacted = \"REDACTED\"\n # Remove the previously set secret data - Not bothering to parse it as this annotation shouldn't ever be needed\n del(.request.object.metadata.annotations.[\"kubectl.kubernetes.io/last-applied-configuration\"])\n del(.request.oldObject.metadata.annotations.[\"kubectl.kubernetes.io/last-applied-configuration\"])\n }\n```", + "details": "### Impact\n_What kind of vulnerability is it? Who is impacted?_\nIf the \"full-elastic-stack\" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\nThe example has been updated to fix this in commit 9df8886b4819409f566233adc7c3b7a43a4096ba\n\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\nReplace \n```yaml\n\n if .request.requestKind.kind == \"Secret\" {\n del(.request.object.data)\n .request.object.data.redacted = \"REDACTED\"\n del(.request.oldObject.data)\n .request.oldObject.data.redacted = \"REDACTED\"\n }\n```\nIn the vector \"audit-files-json-parser-and-redaction\" step\nwith\n```yaml\n\n if .request.requestKind.kind == \"Secret\" {\n # Redact the secret data\n del(.request.object.data)\n .request.object.data.redacted = \"REDACTED\"\n del(.request.oldObject.data)\n .request.oldObject.data.redacted = \"REDACTED\"\n # Remove the previously set secret data - Not bothering to parse it as this annotation shouldn't ever be needed\n del(.request.object.metadata.annotations.[\"kubectl.kubernetes.io/last-applied-configuration\"])\n del(.request.oldObject.metadata.annotations.[\"kubectl.kubernetes.io/last-applied-configuration\"])\n }\n```\n\n\n### References\n_Are there any links users can visit to find out more?_", "severity": [ { "type": "CVSS_V4", @@ -28,7 +28,7 @@ "introduced": "0" }, { - "fixed": "0.0.0-20250129191722-db1aa5b86725" + "fixed": "0.0.0-20250205113217-9df8886b4819" } ] } @@ -51,6 +51,10 @@ { "type": "PACKAGE", "url": "https://github.com/RichardoC/kube-audit-rest" + }, + { + "type": "WEB", + "url": "https://pkg.go.dev/vuln/GO-2025-3431" } ], "database_specific": {