VYPR
Medium severity6.5GHSA Advisory· Published Sep 5, 2025· Updated Apr 15, 2026

CVE-2025-7445

CVE-2025-7445

Description

Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
sigs.k8s.io/secrets-store-sync-controllerGo
< 0.0.20.0.2

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.