Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6g8q-hp2j-gvwv Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 12:45:00 +0000

Type Values Removed Values Added
Description Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.
Title Harvest may expose OS default ssh login password via SUSE Virtualization Interactive Installer
Weaknesses CWE-1188
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-01-08T14:43:34.114Z

Reserved: 2025-10-24T10:34:22.765Z

Link: CVE-2025-62877

cve-icon Vulnrichment

Updated: 2026-01-08T14:41:56.620Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-08T13:15:41.923

Modified: 2026-01-08T18:08:18.457

Link: CVE-2025-62877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses