A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Mar 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 17 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Mar 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation. | |
| Title | Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acm | |
| First Time appeared |
Redhat
Redhat acm Redhat multicluster Engine |
|
| Weaknesses | CWE-922 | |
| CPEs | cpe:/a:redhat:acm:2 cpe:/a:redhat:multicluster_engine |
|
| Vendors & Products |
Redhat
Redhat acm Redhat multicluster Engine |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2025-03-17T16:27:20.598Z
Updated: 2025-09-25T02:43:26.086Z
Reserved: 2025-03-12T04:52:38.166Z
Link: CVE-2025-2241
Updated: 2025-03-17T17:11:44.332Z
Status : Received
Published: 2025-03-17T17:15:40.393
Modified: 2025-03-17T17:15:40.393
Link: CVE-2025-2241