Database/Control plane, storage & DevOps
VMware Aria Operations for Logs (credential disclosure): A View Only Admin reads the credentials of other VMware
CVSS 8.5CVE-2025-22218Control plane, storage & DevOpscurated
Impact
A View Only Admin reads the credentials of other VMware products integrated with Aria Operations for Logs - so the lowest-privilege admin role yields credentials for vCenter and friends.
Who can reach it
Authenticated View Only Admin on Aria Operations for Logs.
What to do
Apply the Broadcom fix per advisory 25329, then rotate the integration credentials that were stored - anyone holding that role could already have read them.
References
Related entries
- VMware vCenter (SMTP header injection via scheduled tasks): A non-administrative user with scheduled-task permissionsCVE-2025-41250 · VMware vCenter (SMTP header injection via scheduled tasks)High
- AMD NBIO register lock bits - System Management Network access: NBIO registers that should be locked after boot areCVE-2025-61972 · AMD NBIO register lock bits - System Management Network accessHigh
- Pure Storage FlashBlade logging: Sensitive material ends up in FlashBlade logs under certain conditions, and the scoredCVE-2026-0207 · Pure Storage FlashBlade loggingHigh
- GitLab package registry: authenticated path traversal that can lead to remote code executionCVE-2026-10053 · GitLab CE/EE package registryHigh
- GitLab: developer-role user can run pipelines on a protected branch without push rightsCVE-2026-15423 · GitLab CE/EE (CI/CD pipeline reference authorization)High
- GitLab EE: authenticated user can attribute AI usage to another namespaceCVE-2026-19228 · GitLab EE (AI feature usage attribution / request identity authorization)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.