Intel

AIKIDO-2025-10533

github.com/jaegertracing/jaeger is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 7, 2025

15

Low Risk

This Affects:

GOgithub.com/jaegertracing/jaeger
1.0.0 - 1.71.0
Fixed in 1.72.0
2.0.0 - 2.8.0
Fixed in 2.9.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to information disclosure due to clear-text logging of sensitive file paths in FSWatcher, where error handling exposed full file paths in plain-text logs due to unsafe logging practices. Specifically, the FSWatcher component logged unreadable file paths during failures, directly revealing sensitive system paths. Attackers compromising log storage or intercepting log streams could exploit this to map critical file locations (e.g., auth.env, config.yaml) and subsequently target these paths for credential theft, configuration tampering, or lateral movement.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/jaegertracing/jaeger is vulnerable to Insertion of Sensitive Information into Log File in versions 1.0.0 - 1.71.0 and 2.0.0 - 2.8.0.

How to fix this

Upgrade the github.com/jaegertracing/jaeger library to the patch version.