CVE-2025-8904: Privilege escalation issue in Amazon EMR Secret Agent component
Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges.
Users are advised to upgrade to Amazon EMR version 7.5 or higher. For Amazon EMR releases between 6.10 and 7.4, we strongly recommend that you run the bootstrap script and RPM files with the fix provided in the location below.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8904?
CVE-2025-8904 is considered a high severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2025-8904?
To fix CVE-2025-8904, users should upgrade their Amazon EMR to a version later than 7.4 or above.
What are the potential risks associated with CVE-2025-8904?
The potential risks include unauthorized access to sensitive Kerberos credentials, leading to privilege escalation.
Which versions of Amazon EMR are affected by CVE-2025-8904?
CVE-2025-8904 affects Amazon EMR versions between 6.10 and 7.4 inclusive.
Who is impacted by CVE-2025-8904?
Any user with access to the /tmp/ directory on affected versions of Amazon EMR may be impacted by CVE-2025-8904.