logo

CVE-2025-2241 github.com/openshift/hive

Package

Manager: go
Name: github.com/openshift/hive
Vulnerable Version: >=0 <=1.1.16

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

EPSS: 0.00053 pctl0.16542

Details

Openshift Hive Exposes VCenter Credentials via ClusterProvision A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

Metadata

Created: 2025-03-17T18:31:53Z
Modified: 2025-03-17T21:27:56Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-c339-mwfc-fmr2/GHSA-c339-mwfc-fmr2.json
CWE IDs: ["CWE-922"]
Alternative ID: GHSA-c339-mwfc-fmr2
Finding: F038
Auto approve: 1