Vulnerability record · CVE-2020-25655 · published 9 November 2020
CVE-2020-25655: Redhat advanced cluster management for kubernetes incorrect authorization vulnerability
Redhat · Advanced Cluster Management For Kubernetes
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster secrets that should only be disclosed to admin users.
Description
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster secrets that should only be disclosed to admin users.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25655 | Issue TrackingVendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25655 | Issue TrackingVendor Advisory |
Track CVE-2020-25655 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-25655), CISA KEV, FIRST EPSS (scores of 2026-10-08). This page is refreshed as NVD updates the record.