CVE-2025-6017 Information
Jul 04, 2025
cve
Description
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10 before 2.10.7 2.11 before 2.11.4 and 2.12 before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and may result in the loss of confidentiality of administrative information which could be leaked to unauthorized actors.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://access.redhat.com/security/cve/CVE-2025-6017 https://bugzilla.redhat.com/show_bug.cgi?id=2372362
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
5.5
Related CNNVD
CNNVD-202507-089 (Published: 2025-07-02)
Share on: