Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.vOnly instances using private helm repositories (i.e setting username & password in the catalogs configuration) are affected. This is fixed in version 4.9.0.
History

Fri, 05 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
Description Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.vOnly instances using private helm repositories (i.e setting username & password in the catalogs configuration) are affected. This is fixed in version 4.9.0.
Title Onyxia private helm repository credentials are leaked through unauthenticated API
Weaknesses CWE-522
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-09-05T21:29:46.796Z

Reserved: 2025-08-29T16:19:59.012Z

Link: CVE-2025-58366

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-05T22:15:34.527

Modified: 2025-09-05T22:15:34.527

Link: CVE-2025-58366

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.