Логотип exploitDog
bind:CVE-2025-2241
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-2241

Количество 4

Количество 4

redhat логотип

CVE-2025-2241

10 месяцев назад

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2025-2241

10 месяцев назад

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-c339-mwfc-fmr2

10 месяцев назад

Openshift Hive Exposes VCenter Credentials via ClusterProvision

CVSS3: 8.2
EPSS: Низкий
fstec логотип

BDU:2025-02918

10 месяцев назад

Уязвимость компонента Hive программного обеспечения управления кластерами Kubernetes Multicluster Engine (MCE) и Advanced Cluster Management (ACM), позволяющая нарушителю получить несанкционированный доступ к учетным данным VCenter

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-2241

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

CVSS3: 8.2
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-2241

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

CVSS3: 8.2
0%
Низкий
10 месяцев назад
github логотип
GHSA-c339-mwfc-fmr2

Openshift Hive Exposes VCenter Credentials via ClusterProvision

CVSS3: 8.2
0%
Низкий
10 месяцев назад
fstec логотип
BDU:2025-02918

Уязвимость компонента Hive программного обеспечения управления кластерами Kubernetes Multicluster Engine (MCE) и Advanced Cluster Management (ACM), позволяющая нарушителю получить несанкционированный доступ к учетным данным VCenter

CVSS3: 8.2
0%
Низкий
10 месяцев назад

Уязвимостей на страницу