Sensitive Token Exposure in Rucio Components by Rucio Software
CVE-2025-54064

6.9MEDIUM

Key Information:

Vendor

Rucio

Vendor
CVE Published:
17 July 2025

What is CVE-2025-54064?

In Rucio, the common helm-charts for the rucio-server, rucio-ui, and rucio-webui unnecessarily log sensitive information, including access tokens, in the apache access log. This logging exposes user credentials such as Internal Rucio tokens or JWTs, posing significant security risks, especially if logs are accessible to non-administrators. Although token truncation may limit immediate usability, the partial credentials should remain confidential. It is crucial to apply the latest updates for these components or adjust the logFormat variable to prevent exposure.

Affected Version(s)

helm-charts rucio-server < 32.0.1 < rucio-server 32.0.1

helm-charts rucio-server >= 33.0.0, < 35.0.1 < rucio-server 33.0.0, 35.0.1

helm-charts rucio-server >= 36.0.0, < 37.0.2 < rucio-server 36.0.0, 37.0.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.