VDB

CVE-2025-6017

CVE-2025-6017 PUBLISHED CVSS 5.5 MEDIUM

A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and may result in the loss of confidentiality of administrative information, which could be leaked to unauthorized actors.

EPSS 0.13% · 2.6th percentile

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.13%
2.6th percentile

Affected Products

VendorProductVersions
redhatadvanced_cluster_management_for_kubernetes2.10, 2.11, 2.12
Red HatRed Hat Advanced Cluster Management for Kubernetes 2
0

Timeline

  • Jul 2, 2025 EPSS Score
  • Jul 2, 2025 Coalition ESS Score
  • Jul 2, 2025 CVE Published
  • Jul 2, 2025 PoC Published
  • Jul 3, 2025 Coalition ESS Score
  • Jul 12, 2025 EPSS Score
  • Jul 22, 2025 EPSS Score
  • Jul 31, 2025 EPSS Score
  • Aug 10, 2025 EPSS Score
  • Aug 20, 2025 EPSS Score
  • Aug 20, 2025 Coalition ESS Score
  • Aug 22, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›