{"id":"CVE-2025-24884","aliases":["GHSA-hcr5-wv4p-h2g2","GO-2025-3431"],"url":"https://o3.security/vulnerability/CVE-2025-24884","summary":"kube-audit-rest's example logging configuration could disclose secret values in the audit log","details":"kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the \"full-elastic-stack\" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages. This vulnerability is fixed in 1.0.16.","published":"2025-01-29T20:15:39.454Z","modified":"2026-08-08T03:48:11.950793905Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/RichardoC/kube-audit-rest","fixedVersion":"0.0.0-20250205113217-9df8886b4819"}],"fix":{"url":"https://github.com/RichardoC/kube-audit-rest/commit/db1aa5b867256b0a7bf206544c6981ab068b73dc","label":"RichardoC/kube-audit-rest@db1aa5b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24884.json"},{"type":"ADVISORY","url":"https://github.com/RichardoC/kube-audit-rest/security/advisories/GHSA-hcr5-wv4p-h2g2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24884"},{"type":"FIX","url":"https://github.com/RichardoC/kube-audit-rest/commit/db1aa5b867256b0a7bf206544c6981ab068b73dc"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:11.950793905Z"}}