FlawAtlas
Search the atlas
CVE-2025-2241 High

Openshift Hive Exposes VCenter Credentials via ClusterProvision in github.com/openshift/hive

Openshift Hive Exposes VCenter Credentials via ClusterProvision in github.com/openshift/hive

Exploit probability 0.5%
Published March 18, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

36 explicit affected versions

Go github.com/openshift/hive
Go github.com/openshift/hive

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-c339-mwfc-fmr2

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

View original source
Open Source Vulnerabilities GO-2025-3529

Openshift Hive Exposes VCenter Credentials via ClusterProvision in github.com/openshift/hive

View original source
Open Source Vulnerabilities CVE-2025-2241

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

View original source

05 / REFERENCES

Further evidence