CVE-2025-66411
HIGH7.8EPSS 0.04%Coder logs sensitive objects unsanitized
描述
## Summary Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized ## Details By default Workspace Agent logs are redirected to [stderr](https://linux.die.net/man/3/stderr) https://github.com/coder/coder/blob/a8862be546f347c59201e2219d917e28121c0edb/cli/agent.go#L432-L439 [Workspace Agent Manifests](https://coder.com/docs/reference/agent-api/schemas#agentsdkmanifest) containing sensitive environment variables were logged insecurely https://github.com/coder/coder/blob/7beb95fd56d2f790502e236b64906f8eefb969bd/agent/agent.go#L1090 An attacker with limited local access to the Coder Workspace (VM, K8s Pod etc.) or a third-party system ([SIEM](https://csrc.nist.gov/glossary/term/security_information_and_event_management_tool), logging stack) could access those logs This behavior opened room for unauthorized access and privilege escalation ## Impact Impact varies depending on the environment variables set in a given workspace ## Patches [Fix](https://github.com/coder/coder/commit/e2a46393fce40bc630df3293c1ee66a596277289) was released & backported: - https://github.com/coder/coder/releases/tag/v2.28.4 - https://github.com/coder/coder/releases/tag/v2.27.7 - https://github.com/coder/coder/releases/tag/v2.26.5 ## Workarounds One potential workaround is to disable Workspace Agent Logs by setting following configuration option `CODER_AGENT_LOGGING_HUMAN=/dev/null` > platform operators are advised to upgrade their deployments
受影響套件(3)
- Go/github.com/coder/coderfrom 0
- Go/github.com/coder/coder/v2from 0, < 2.26.5
- Go/github.com/coder/coder/v2from 0, < 2.26.5, >= 2.27.0, < 2.27.7, >= 2.28.0, < 2.28.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
參考連結(10)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-66411
- PATCHhttps://github.com/coder/coder
- WEBhttps://github.com/coder/coder/commit/06c6abbe0935f9213c1588add60a396da5762e1c
- WEBhttps://github.com/coder/coder/commit/a75205a559211c8aa494b1a16750d114b263f24a
- WEBhttps://github.com/coder/coder/commit/e2a46393fce40bc630df3293c1ee66a596277289
- WEBhttps://github.com/coder/coder/pull/20968
- WEBhttps://github.com/coder/coder/releases/tag/v2.26.5
- WEBhttps://github.com/coder/coder/releases/tag/v2.27.7
- WEBhttps://github.com/coder/coder/releases/tag/v2.28.4
- WEBhttps://github.com/coder/coder/security/advisories/GHSA-jf75-p25m-pw74