A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.
History

Tue, 18 Mar 2025 02:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 17 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.
Title Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acm
First Time appeared Redhat
Redhat acm
Redhat multicluster Engine
Weaknesses CWE-922
CPEs cpe:/a:redhat:acm:2
cpe:/a:redhat:multicluster_engine
Vendors & Products Redhat
Redhat acm
Redhat multicluster Engine
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-03-17T17:11:48.110Z

Reserved: 2025-03-12T04:52:38.166Z

Link: CVE-2025-2241

cve-icon Vulnrichment

Updated: 2025-03-17T17:11:44.332Z

cve-icon NVD

Status : Received

Published: 2025-03-17T17:15:40.393

Modified: 2025-03-17T17:15:40.393

Link: CVE-2025-2241

cve-icon Redhat

Severity : Important

Publid Date: 2025-03-17T15:52:50Z

Links: CVE-2025-2241 - Bugzilla