Intel

AIKIDO-2025-10938

github.com/zalando/skipper is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 15, 2025

30

Low Risk

This Affects:

GOgithub.com/zalando/skipper
0.10.157 - 0.22.186
Fixed in 0.22.187
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to information disclosure due to Inadequate Masking of Sensitive Query Parameters in Access Logs, where the abscense of a proper redaction filter fails to properly obfuscate all sensitive query parameters, potentially leaving credentials or tokens exposed in access logs; an attacker could exploit this by accessing or intercepting these logs to harvest unmasked data, leading to account compromise or further system intrusion.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/zalando/skipper is vulnerable to Insertion of Sensitive Information into Log File in versions 0.10.157 - 0.22.186.

How to fix this

Upgrade the github.com/zalando/skipper library to the patch version.