← Back

CVE-2023-24619

nvd nist
Published: Feb 13, 2023Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

Redpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk binary logs an AWS Access Key ID and Secret in cleartext to standard output, allowing a local user to view the key in the console, or in Kubernetes logs if stdout output is collected. The fixed versions are 22.3.12, 22.2.10, and 22.1.12.

Affected (3)

Products: Redpanda: Redpanda
1 product
Redpanda
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Redpanda
From 22.1.0 to 22.1.12
From 22.2.0 to 22.2.10
From 22.3.0 to 22.3.12

References (2)

Source: cve@mitre.org
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory

Timeline

No history available yet.