This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0.
Users are recommended to upgrade to version 2.14.0, which fixes the issue.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 04 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:kvrocks:*:*:*:*:*:*:*:* |
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache kvrocks |
|
| Vendors & Products |
Apache
Apache kvrocks |
Fri, 28 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 28 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-312 | |
| Metrics |
cvssV3_1
|
Fri, 28 Nov 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue. | |
| Title | Apache Kvrocks: MONITOR command reveals plaintext credentials to non-admins | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-11-28T17:03:57.700Z
Reserved: 2025-09-21T04:00:36.588Z
Link: CVE-2025-59792
Updated: 2025-11-28T17:03:57.700Z
Status : Analyzed
Published: 2025-11-28T15:16:03.140
Modified: 2025-12-04T17:04:38.183
Link: CVE-2025-59792
No data.
OpenCVE Enrichment
Updated: 2025-12-01T15:18:30Z