5.5
CVE-2025-6017
- EPSS 0.02%
- Published 02.07.2025 06:36:47
- Last modified 20.08.2025 16:33:58
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and may result in the loss of confidentiality of administrative information, which could be leaked to unauthorized actors.
Data is provided by the National Vulnerability Database (NVD)
Redhat ≫ Advanced Cluster Management For Kubernetes Version >= 2.10 < 2.10.7
Redhat ≫ Advanced Cluster Management For Kubernetes Version >= 2.11 < 2.11.4
Redhat ≫ Advanced Cluster Management For Kubernetes Version >= 2.12 < 2.12.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.021 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
secalert@redhat.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.