Duplicate Advisory: k8s.io/kube-state-metrics Exposure of Sensitive Information
Moderate severity
GitHub Reviewed
Published
May 18, 2021
to the GitHub Advisory Database
•
Updated Jan 23, 2024
Withdrawn
This advisory was withdrawn on Jan 23, 2024
Description
Reviewed
May 17, 2021
Published to the GitHub Advisory Database
May 18, 2021
Last updated
Jan 23, 2024
Withdrawn
Jan 23, 2024
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-c92w-72c5-9x59. This link is maintained to preserve external references.
Original Description
A security issue was discovered in kube-state-metrics 1.7.x before 1.7.2. An experimental feature was added to v1.7.0 and v1.7.1 that enabled annotations to be exposed as metrics. By default, kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default kubectl behavior and this new feature can cause the entire secret content to end up in metric labels, thus inadvertently exposing the secret content in metrics.
References