A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Mar 2025 02:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Mon, 17 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 17 Mar 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation. | |
Title | Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acm | |
First Time appeared |
Redhat
Redhat acm Redhat multicluster Engine |
|
Weaknesses | CWE-922 | |
CPEs | cpe:/a:redhat:acm:2 cpe:/a:redhat:multicluster_engine |
|
Vendors & Products |
Redhat
Redhat acm Redhat multicluster Engine |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published: 2025-03-17T16:27:20.598Z
Updated: 2025-03-17T17:11:48.110Z
Reserved: 2025-03-12T04:52:38.166Z
Link: CVE-2025-2241

Updated: 2025-03-17T17:11:44.332Z

Status : Received
Published: 2025-03-17T17:15:40.393
Modified: 2025-03-17T17:15:40.393
Link: CVE-2025-2241
