Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c339-mwfc-fmr2

Опубликовано: 17 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

Openshift Hive Exposes VCenter Credentials via ClusterProvision

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

Пакеты

Наименование

github.com/openshift/hive

go
Затронутые версииВерсия исправления

<= 1.1.16

Отсутствует

EPSS

Процентиль: 33%
0.00129
Низкий

8.2 High

CVSS3

Дефекты

CWE-922

Связанные уязвимости

CVSS3: 8.2
redhat
11 месяцев назад

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

CVSS3: 8.2
nvd
11 месяцев назад

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

CVSS3: 8.2
fstec
11 месяцев назад

Уязвимость компонента Hive программного обеспечения управления кластерами Kubernetes Multicluster Engine (MCE) и Advanced Cluster Management (ACM), позволяющая нарушителю получить несанкционированный доступ к учетным данным VCenter

EPSS

Процентиль: 33%
0.00129
Низкий

8.2 High

CVSS3

Дефекты

CWE-922