CVE-2025-24884: Richardoc Kube-Audit-Rest

Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.

kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages. This vulnerability is fixed in 1.0.16.

Affected products

  • Richardoc Kube-Audit-Rest: before 1.0.16 (fixed in 1.0.16)

Published 2025-01-29. Last modified 2026-06-17.