A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and may result in the loss of confidentiality of administrative information, which could be leaked to unauthorized actors.
History

Wed, 02 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Jul 2025 12:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 02 Jul 2025 06:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and may result in the loss of confidentiality of administrative information, which could be leaked to unauthorized actors.
Title Rhacm: users with clusterreader role can see credentials from managed-clusters
First Time appeared Redhat
Redhat acm
Weaknesses CWE-359
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-07-02T13:13:39.278Z

Reserved: 2025-06-11T21:09:21.420Z

Link: CVE-2025-6017

cve-icon Vulnrichment

Updated: 2025-07-02T13:13:33.871Z

cve-icon NVD

Status : Received

Published: 2025-07-02T07:15:23.293

Modified: 2025-07-02T07:15:23.293

Link: CVE-2025-6017

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-07-02T06:33:03Z

Links: CVE-2025-6017 - Bugzilla