PT-2025-36106 · Unknown · Kubernetes Secrets-Store-Sync-Controller

Kas Dekel

+1

·

Published

2025-09-05

·

Updated

2025-09-22

·

CVE-2025-7445

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kubernetes secrets-store-sync-controller versions prior to 0.0.2
Description The Kubernetes secrets-store-sync-controller discloses service account tokens in logs.
Recommendations Update to version 0.0.2 or later.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-7445
GHSA-RCW7-PQFP-735X
GO-2025-3939
OPENSUSE-SU-2025:15564-1
SUSE-SU-2025:03289-1

Affected Products

Kubernetes Secrets-Store-Sync-Controller