{"schema_version":"1.9.0","id":"CVE-2025-24884","published":"2025-01-29T20:15:39.454Z","modified":"2026-08-12T03:51:47.574648236Z","aliases":["GHSA-hcr5-wv4p-h2g2","GO-2025-3431"],"related":["SUSE-SU-2025:0429-1","openSUSE-SU-2025:14732-1"],"summary":"kube-audit-rest's example logging configuration could disclose secret values in the audit log","details":"kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the \"full-elastic-stack\" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages. This vulnerability is fixed in 1.0.16.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/richardoc/kube-audit-rest","events":[{"introduced":"0"},{"fixed":"db1aa5b867256b0a7bf206544c6981ab068b73dc"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.0.16"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.0.15","1.0.14","1.0.13","1.0.12","1.0.11","1.0.10","1.0.9","1.0.8","1.0.7","1.0.6","1.0.5","1.0.4","1.0.3","1.0.2","1.0.1","1.0.0","0.0.7","0.0.6","0.0.5","0.0.4","0.0.2","0.0.1","0.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-24884.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24884.json"},{"type":"ADVISORY","url":"https://github.com/RichardoC/kube-audit-rest/security/advisories/GHSA-hcr5-wv4p-h2g2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24884"},{"type":"FIX","url":"https://github.com/RichardoC/kube-audit-rest/commit/db1aa5b867256b0a7bf206544c6981ab068b73dc"}],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-200","CWE-212","CWE-532"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24884.json"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}