Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jf75-p25m-pw74

Опубликовано: 03 дек. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Coder logs sensitive objects unsanitized

Summary

Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized

Details

By default Workspace Agent logs are redirected to stderr https://github.com/coder/coder/blob/a8862be546f347c59201e2219d917e28121c0edb/cli/agent.go#L432-L439

Workspace Agent Manifests containing sensitive environment variables were logged insecurely https://github.com/coder/coder/blob/7beb95fd56d2f790502e236b64906f8eefb969bd/agent/agent.go#L1090

An attacker with limited local access to the Coder Workspace (VM, K8s Pod etc.) or a third-party system (SIEM, logging stack) could access those logs

This behavior opened room for unauthorized access and privilege escalation

Impact

Impact varies depending on the environment variables set in a given workspace

Patches

Fix was released & backported:

Workarounds

One potential workaround is to disable Workspace Agent Logs by setting following configuration option CODER_AGENT_LOGGING_HUMAN=/dev/null

platform operators are advised to upgrade their deployments

Пакеты

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

< 2.26.5

2.26.5

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.27.0, < 2.27.7

2.27.7

Наименование

github.com/coder/coder/v2

go
Затронутые версииВерсия исправления

>= 2.28.0, < 2.28.4

2.28.4

EPSS

Процентиль: 3%
0.00015
Низкий

7.8 High

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 7.8
nvd
2 месяца назад

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized. An attacker with limited local access to the Coder Workspace (VM, K8s Pod etc.) or a third-party system (SIEM, logging stack) could access those logs. This vulnerability is fixed in 2.26.5, 2.27.7, and 2.28.4.

EPSS

Процентиль: 3%
0.00015
Низкий

7.8 High

CVSS3

Дефекты

CWE-532