CVE-2025-6017
published 2025-07-02CVE-2025-6017: A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability…
PriorityP428medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.13%
2.7th percentile
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and may result in the loss of confidentiality of administrative information, which could be leaked to unauthorized actors.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | advanced_cluster_management_for_kubernetes | >= 2.10 < 2.10.7 | 2.10.7 |
| redhat | advanced_cluster_management_for_kubernetes | >= 2.11 < 2.11.4 | 2.11.4 |
| redhat | advanced_cluster_management_for_kubernetes | >= 2.12 < 2.12.4 | 2.12.4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g8pw-ch7g-q2vc: A flaw was found in Red Hat Advanced Cluster Management through versions 2
ghsa_unreviewed·2025-07-02
CVE-2025-6017 [MEDIUM] CWE-359 GHSA-g8pw-ch7g-q2vc: A flaw was found in Red Hat Advanced Cluster Management through versions 2
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and may result in the loss of confidentiality of administrative information, which could be leaked to unauthorized actors.
Red Hat
rhacm: Users with ClusterReader Role can see credentials from Managed-clusters
vendor_redhat·2025-07-02·CVSS 5.5
CVE-2025-6017 [MEDIUM] CWE-359 rhacm: Users with ClusterReader Role can see credentials from Managed-clusters
rhacm: Users with ClusterReader Role can see credentials from Managed-clusters
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and may result in the loss of confidentiality of administrative information, which could be leaked to unauthorized actors.
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only
No detection rules found.
No public exploits indexed.
2025-07-02
Published