Intel

AIKIDO-2025-10333

github.com/fluxcd/kustomize-controller is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

15

Low Risk

This Affects:

GOgithub.com/fluxcd/kustomize-controller
0.2.0 - 1.5.0
Fixed in 1.5.1

TL;DR

Affected versions of this package are vulnerable to the exposure of sensitive data in logs due to improper handling of decryption in the Kustomize controller. This issue occurs when a secret resource is initially set to an empty string in the base layer and later updated with actual secret data. As a result, the controller mistakenly decrypts and logs the secret value. If the controller publicly logs are exposed or kept in a system with less authorization, an attacker could potentially gain access to sensitive data.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/fluxcd/kustomize-controller is vulnerable to Insertion of Sensitive Information into Log File in versions 0.2.0 - 1.5.0.

How to fix this

Upgrade the github.com/fluxcd/kustomize-controller library to the patch version.