GHSA-xggc-qprg-x6mw
CRITICALCVE-2022-31098A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to view sensitive cluster configurations, aka KubeConfg, of registered Kubernetes clusters, including the service account tokens in plain text from Weave GitOps's pod logs on the management cluster. An unauthorized remote attacker can also view these sensitive configurations from external log storage if ena
- Affected
- <= 0.8.1-rc.5
- Fixed in
- 0.8.1-rc.6
- Weakness
- CWE-200
- Published
- 2022-06-23
- Source
- github