Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-71425— Contrast before 1.8.1 Information Disclosure via Logging

Quick assessment

Affected
edgelesssys contrast
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Contrast(由 Edgeless Systems 开发)1.8.1 之前的版本在将 Contrast 初始化程序(initializer)的日志级别配置为 info 或 debug 时,会将工作负载密钥(workload secret)记录到标准错误输出(stderr),进而写入 Kubernetes 日志中。由于 info 是默认日志级别,因此所有未自定义初始化程序日志级别的安装均受到影响。 这会导致原本仅对 Contrast 协调器(Coordinator)、初始化程序、种子共享持有者(seedshare

CVSS 7.3 · High EPSS 0.19% · P8

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-71425

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Contrast before 1.8.1 Information Disclosure via Logging
Source: CVE Program / CVE List V5
Vulnerability Description
Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affected. This exposes workload secrets — normally accessible only to the Contrast Coordinator, the initializer, the seedshare owner, and the workload owner — to Kubernetes users with get or list permission on pods/logs and to anyone with read access to the Kubernetes log storage, such as the cloud provider. Deployments that do not use workload secrets are unaffected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过日志文件的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
edgelesssys contrast 0 ~ 1.8.1 -

II. Public POCs for CVE-2025-71425

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-71425

请登录查看更多情报信息。

Vendor Advisories for CVE-2025-71425 (1)

Other References for CVE-2025-71425 (1)

Same Patch Batch · edgelesssys · 2026-09-27 · 11 CVEs total

CVE-2026-100839 8.4 HIGH Contrast before 1.18.0 AML Injection Remote Code Execution
CVE-2026-100833 8.2 HIGH Contrast before 1.23.1 Image Substitution via Policy Generation
CVE-2026-100838 8.1 HIGH Contrast before 1.19.1 CopyFile Policy Symlink Subversion
CVE-2026-100835 7.4 HIGH Contrast before 1.16.0 Remote Attestation Relay Attack
CVE-2025-71423 7.3 HIGH Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure
CVE-2025-71426 7.1 HIGH Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery
CVE-2025-71422 5.7 MEDIUM Contrast before 1.12.1 Insecure LUKS2 Persistent Storage
CVE-2026-100836 4.3 MEDIUM Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer
CVE-2026-100837 3.7 LOW Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching
CVE-2025-71424 3.5 LOW Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount

IV. Related Vulnerabilities

V. Comments for CVE-2025-71425

No comments yet


Leave a comment