GHSA-c339-mwfc-fmr2
HIGHCVE-2025-2241A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lea
- Affected
- >=0
- Fixed in
- not stated
- Weakness
- CWE-922
- Published
- 2025-03-17
- Source
- github