Impact
An insertion of sensitive information into log files caused SUSE NeuVector’s manager container to expose confidential data. The flaw violates the confidentiality of stored credentials, tokens, or other secrets, pursuant to the Common Weakness Enumeration CWE‑532. This leads to a breach of privacy and may enable attackers to leverage the leaked data for further intrusion or account compromises.
Affected Systems
The vulnerability affects the SUSE NeuVector manager component. Any deployment using a NeuVector version earlier than 5.4.5 is susceptible. The issue is confined to the manager container instance and its associated log files.
Risk and Exploitability
With a CVSS score of 6.8, the vulnerability is considered medium severity. Although an EPSS score is not available, the lack of a CISA KEV listing indicates no known large‑scale exploitation as of now. The likely attack vector is an attacker who can influence the manager to log sensitive data—either through a local compromise or by manipulating application inputs that trigger logging paths. The risk is elevated for environments where logs are accessible to privileged users or exposed externally.
OpenCVE Enrichment