The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the kuadrant-system instead of copying it to the referred namespace. This creates space for a malicious actor with a developer persona access to leak those secrets over HTTP connection, as long the attacker knows the name of the targeted secrets and those secrets are limited to one line only.
History

Mon, 09 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Jun 2025 06:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the kuadrant-system instead of copying it to the referred namespace. This creates space for a malicious actor with a developer persona access to leak those secrets over HTTP connection, as long the attacker knows the name of the targeted secrets and those secrets are limited to one line only.
Title RHCL: sharedSecretRef Can Be Used To Leak Secrets Severity Rhcl: sharedsecretref can be used to leak secrets severity
First Time appeared Redhat
Redhat connectivity Link
CPEs cpe:/a:redhat:connectivity_link:1
Vendors & Products Redhat
Redhat connectivity Link
References

Tue, 25 Feb 2025 13:45:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title RHCL: sharedSecretRef Can Be Used To Leak Secrets Severity
Weaknesses CWE-200
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2025-06-09T06:13:56.342Z

Updated: 2025-06-09T13:23:23.962Z

Reserved: 2025-02-03T20:02:01.750Z

Link: CVE-2025-25209

cve-icon Vulnrichment

Updated: 2025-06-09T13:23:21.446Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-09T06:15:24.853

Modified: 2025-06-09T12:15:47.880

Link: CVE-2025-25209

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-02-24T00:00:00Z

Links: CVE-2025-25209 - Bugzilla