Impact
A flaw in the must‑gather component of Red Hat Advanced Cluster Management for Kubernetes causes ACM wrapper Custom Resources that embed Secret data to be collected without redaction. When an administrator executes must‑gather, the resulting archive contains credentials and tokens in cleartext, allowing anyone who can read the archive to obtain sensitive authentication information. This can lead to unauthorized disclosure of authentication data.
Affected Systems
The vulnerability is limited to Red Hat Advanced Cluster Management for Kubernetes 2, the product identified by the CNA as affected.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium impact. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, so widespread exploitation is not yet documented. The likely attack vector is an authenticated user who can run must‑gather; if the produced archive is stored or transferred, an attacker who can access it can read the exposed credentials. Because the flaw manifests during normal use of must‑gather, the risk is moderate but non‑zero.
OpenCVE Enrichment