VDB

GCVE-110-CLOUD-2025-0047

GCVE-110-CLOUD-2025-0047
Advisory Published
Vulnetix · Advisory published February 26, 2025
AWS EKS was logging ServiceAccount tokens in plaintext, including those used for AssumeRoleWithWebIdentity and connecting to the Kubernetes API server. This issue affected clusters between March 2020 and May 2021, potentially exposing sensitive credentials in CloudWatch logs.

Affected Products

VendorProductVersionsPlatforms
AWSConnect
AWSCloudWatch
AWSEKS

Browse GCVE Records

74,237 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›