First published: Tue Mar 11 2025(Updated: )
A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Hive | ||
Red Hat Multicluster Engine | ||
Red Hat Advanced Cluster Management | ||
go/github.com/openshift/hive | <=1.1.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2241 has a high severity due to the exposure of sensitive VCenter credentials.
To fix CVE-2025-2241, update Red Hat Hive, Multicluster Engine (MCE), and Advanced Cluster Management (ACM) to the latest patched versions.
CVE-2025-2241 affects Red Hat Hive, Multicluster Engine (MCE), and Advanced Cluster Management (ACM) software.
CVE-2025-2241 impacts security by potentially allowing unauthorized access to VCenter credentials.
CVE-2025-2241 was disclosed on 2025-03-10.