EdgelessSys Contrast 是一个用于 Kubernetes 的机密计算运行时。在 1.9.0 至 1.12.2 版本(不含 1.12.2)中,初始化程序会将包含工作负载密钥的完整 NewMeshCert 响应以 INFO 级别记录到标准输出。因此,任何对 pod/logs 具有 get 或 list 权限的 Kubernetes 用户都可以获取这些工作负载密钥。由于这些工作负载密钥用于加密存储和 Vault 集成,因此它们也被视为已泄露。此问题是 GHSA-h5f8-crrq-4pw8 的回归漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| edgelesssys | contrast | 1.9.0 ~ 1.12.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100839 | 8.4 HIGH | Contrast before 1.18.0 AML Injection Remote Code Execution |
| CVE-2026-100833 | 8.2 HIGH | Contrast before 1.23.1 Image Substitution via Policy Generation |
| CVE-2026-100838 | 8.1 HIGH | Contrast before 1.19.1 CopyFile Policy Symlink Subversion |
| CVE-2026-100835 | 7.4 HIGH | Contrast before 1.16.0 Remote Attestation Relay Attack |
| CVE-2025-71425 | 7.3 HIGH | Contrast before 1.8.1 Information Disclosure via Logging |
| CVE-2025-71426 | 7.1 HIGH | Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery |
| CVE-2025-71422 | 5.7 MEDIUM | Contrast before 1.12.1 Insecure LUKS2 Persistent Storage |
| CVE-2026-100836 | 4.3 MEDIUM | Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer |
| CVE-2026-100837 | 3.7 LOW | Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching |
| CVE-2025-71424 | 3.5 LOW | Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount |
No comments yet