—
GO-2022-0621
Exposure of sensitive information in k8s.io/kube-state-metrics
Quick fix
GO-2022-0621 — k8s.io/kube-state-metrics: upgrade to the fixed version with the command below.
go get k8s.io/kube-state-metrics@v1.7.2Details
Exposing annotations as metrics can leak secrets.
An experimental feature of kube-state-metrics enables annotations to be exposed as metrics. By default, metrics only expose metadata about secrets. However, a combination of the default kubectl behavior and this new feature can cause the entire secret content to end up in metric labels.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/k8s.io/kube-state-metrics
Introduced in:
1.7.0Fixed in: 1.7.2Fix
go get k8s.io/kube-state-metrics@v1.7.2