Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-25655 – An issue was discovered in ManagedClusterView API, that could allow secre

An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster secrets that should only be disclosed to admin users.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25655

Reference (s):

  • https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25655
  • URL: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25655
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-9235 - Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos

2021-current

CVE-2020-0828 - A remote code execution vulnerability exists in the way that the ChakraCo

2021-current

CVE-2020-14827 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Ser