PT-2025-12666 · Unknown+1 · Kanidm-Provision+1
Published
2025-03-24
·
Updated
2025-03-24
·
CVE-2025-30205
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
kanidm-provision versions prior to 1.2.0
Description
The issue is related to a faulty function instrumentation in the optional kanidm patches provided by kanidm-provision, which causes the provisioned admin credentials to be leaked to the system log. This only affects users who use the provided patches and provision their
admin or idm admin account credentials. No other credentials are affected.Recommendations
For versions prior to 1.2.0, recompile kanidm with the newest patchset from tag
v1.2.0 or higher.
As a temporary workaround, set the log level KANIDM LOG LEVEL to any level higher than info, for example warn.Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kanidm
Kanidm-Provision