Exposing annotations as metrics can leak secrets.
An experimental feature of kube-state-metrics enables annotations to be exposed as metrics. By default, metrics only expose metadata about secrets. However, a combination of the default kubectl behavior and this new feature can cause the entire secret content to end up in metric labels.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0621" }