VCenter Credential Exposure in Multicluster Engine and Advanced Cluster Management
CVE-2025-2241
8.2HIGH
What is CVE-2025-2241?
A significant flaw has been identified in Hive, part of the Multicluster Engine (MCE) and Advanced Cluster Management (ACM), that results in the exposure of VCenter credentials within the ClusterProvision object following the provisioning of a VSphere cluster. This vulnerability allows users with read access to ClusterProvision objects to extract sensitive VCenter credentials, even without direct access to Kubernetes Secrets. Such a flaw poses a risk of unauthorized VCenter access, potential cluster management compromises, and privilege escalation vulnerabilities.