Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12401 | CNCF K3s Kubernetes kubelet configuration exposes credentials |
Github GHSA |
GHSA-864f-7xjm-2jp2 | CNCF K3s Kubernetes kubelet configuration exposes credentials |
Fri, 25 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Apr 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For example, the default behavior of a K3s online installation might allow unauthenticated access to this port, exposing credentials. | |
| Weaknesses | CWE-1188 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-25T14:28:05.811Z
Reserved: 2025-04-25T00:00:00.000Z
Link: CVE-2025-46599
Updated: 2025-04-25T14:28:02.163Z
Status : Deferred
Published: 2025-04-25T05:15:33.330
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-46599
No data.
OpenCVE Enrichment
Updated: 2025-06-23T19:31:58Z
EUVD
Github GHSA