oss-sec mailing list archives

CVE-2025-59792: Apache Kvrocks: MONITOR command reveals plaintext credentials to non-admins


From: Hulk Lin <hulk () apache org>
Date: Fri, 28 Nov 2025 14:00:49 +0000

Severity: important 

Affected versions:

- Apache Kvrocks 1.0.0 through 2.13.0

Description:

Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks.

This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0.

Users are recommended to upgrade to version 2.14.0, which fixes the issue.

Credit:

Mapta / BugBunny_ai (reporter)

References:

https://kvrocks.apache.org
https://www.cve.org/CVERecord?id=CVE-2025-59792


Current thread: