CVE 8.6 HIGH

Omni leaks information via the API_CVE-2025-61688

8.6 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Description

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensitive information via an API.

AI Analysis

AI processing failed - returned non-JSON response

Basic Information

ID CVE-2025-61688
Source GitHub_M
Published Oct 13, 2025 at 20:46

Affected Product

Vendor siderolabs
Product omni
Version >= 1.1.0-beta.0, < 1.1.5
Affected Versions siderolabs omni >= 1.1.0-beta.0, < 1.1.5
siderolabs omni < 1.0.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.