VDB
CVE-2025-6017
CVE-2025-6017
PUBLISHED
CVSS 5.5 MEDIUM
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and may result in the loss of confidentiality of administrative information, which could be leaked to unauthorized actors.
EPSS 0.13% · 2.6th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.13%
2.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | advanced_cluster_management_for_kubernetes | 2.10, 2.11, 2.12 |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | |
| 0 |
Timeline
- Jul 2, 2025 EPSS Score
- Jul 2, 2025 Coalition ESS Score
- Jul 2, 2025 CVE Published
- Jul 2, 2025 PoC Published
- Jul 3, 2025 Coalition ESS Score
- Jul 12, 2025 EPSS Score
- Jul 22, 2025 EPSS Score
- Jul 31, 2025 EPSS Score
- Aug 10, 2025 EPSS Score
- Aug 20, 2025 EPSS Score
- Aug 20, 2025 Coalition ESS Score
- Aug 22, 2025 Coalition ESS Score