Lucene search

K
osvGoogleOSV:GO-2022-0621
HistoryMay 18, 2021 - 3:38 p.m.

Exposure of sensitive information in k8s.io/kube-state-metrics

2021-05-1815:38:54
Google
osv.dev
16
k8s
kube-state-metrics
annotations
metrics
secrets
experimental feature
metadata

AI Score

6.4

Confidence

High

EPSS

0.002

Percentile

64.3%

Exposing annotations as metrics can leak secrets.

An experimental feature of kube-state-metrics enables annotations to be exposed as metrics. By default, metrics only expose metadata about secrets. However, a combination of the default kubectl behavior and this new feature can cause the entire secret content to end up in metric labels.

AI Score

6.4

Confidence

High

EPSS

0.002

Percentile

64.3%