Impact
The vulnerability is in the must‑gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is written to the must‑gather archive in raw form, bypassing the oc inspect redaction that would normally remove sensitive fields. As a result, proxy basic‑auth credentials are captured in the archive and could be viewed by anyone who has access to it. This flaw falls under CWE‑532 – Information Exposure through insecure storage.
Affected Systems
Red Hat Advanced Cluster Management for Kubernetes version 2 is affected. Only this product and version are listed as impacted in the CNA data.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium impact. The EPSS score is not provided, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is indirect; an adversary who gains access to the must‑gather archive—whether through mis‑configured access controls or after a cluster compromise—can read the exposed credentials. Due to the potential credential theft, the risk is considered moderate, especially when archives are shared with external parties.
OpenCVE Enrichment