Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-2241

Опубликовано: 17 мар. 2025
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

EPSS

Процентиль: 29%
0.00101
Низкий

8.2 High

CVSS3

Дефекты

CWE-922

Связанные уязвимости

CVSS3: 8.2
redhat
10 месяцев назад

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

CVSS3: 8.2
github
10 месяцев назад

Openshift Hive Exposes VCenter Credentials via ClusterProvision

CVSS3: 8.2
fstec
10 месяцев назад

Уязвимость компонента Hive программного обеспечения управления кластерами Kubernetes Multicluster Engine (MCE) и Advanced Cluster Management (ACM), позволяющая нарушителю получить несанкционированный доступ к учетным данным VCenter

EPSS

Процентиль: 29%
0.00101
Низкий

8.2 High

CVSS3

Дефекты

CWE-922