CVE-2025-46808
Awaiting Analysis Awaiting Analysis - Queue

Sensitive Information Log Exposure in SUSE NeuVector Manager

Vulnerability report for CVE-2025-46808, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: SUSE

Description

An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
suse neuvector to 5.4.4 (inc)
suse neuvector From 5.4.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves sensitive information being exposed in the NeuVector manager container's logs. Affected versions (up to 5.4.4) log details like Rancher session tokens, GitHub/Azure DevOps tokens, NeuVector tokens, and other sensitive keys during actions such as login or API interactions.

Detection Guidance

Check NeuVector manager logs for exposed sensitive information like tokens or keys. Look for entries containing 'X-R-Sess', 'personal_access_token', 'token1.token', 'Rekor public key', 'root certificate', 'SCT public key', or 'verifier's public key'.

Impact Analysis

If logs are accessed by unauthorized parties, attackers could steal sensitive tokens or keys, leading to potential account takeovers, unauthorized access to repositories, or compromise of NeuVector's security infrastructure. The risk increases with external logging.

Compliance Impact

This vulnerability could violate compliance requirements by exposing sensitive data in logs, potentially leading to unauthorized access or data breaches. Organizations may face penalties under regulations like GDPR or HIPAA for failing to protect such information.

Mitigation Strategies

Upgrade NeuVector to version 5.4.5 or higher to patch the vulnerability. Rotate any exposed GitHub tokens used in remote repository configurations. Ensure log collectors are secured to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-46808. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart