CVE-2025-54467
Aliases:GHSA-w54x-xfxg-4gxqGO-2025-3919CGA-437g-5pwq-v3g3CGA-6rg9-7g9m-g8wrCGA-mv8h-7hpw-c2r2CGA-46mm-3mxp-8rrcCGA-6jjq-j8gr-grrqCGA-ph2h-vw8q-qv65CGA-xg9r-wgjx-gjqgCGA-xm82-rpf9-c27h
Advisory lineage Upstream: 0 Downstream: 3
Deferred
Published: 17 Sept 2025, 12:29
Last modified:17 Sept 2025, 13:19
Vulnerability Summary
Overall Risk (default)
low
21/100 CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.25% LOW
0% probability +0.21%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
17 Sept 2025, 12:29
Published
Vulnerability first disclosed
17 Sept 2025, 13:19
Last Modified
Vulnerability information updated
Description
When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVector security event log.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Trends
Current EPSS score: 0.25%• Percentile: 16%
Techniques & Countermeasures
- CWE-522•Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Affected Systems
- chainguard•neuvector-scanner
< 0
- chainguard•neuvector-scanner-fips
< 0
- chainguard•neuvector-scanner-task
< 0
- chainguard•neuvector-scanner-task-fips
< 0
- wolfi•neuvector-scanner
< 0
- wolfi•neuvector-scanner-task
< 0
- github.com/neuvector•neuvector
≥ 5.0.0, < 5.4.6 | < 0.0.0-20250825231653-65d7e746ce84 | all | < 0.0.0-20250902144615-f9ddbdf42031
- suse•neuvector
≥ 5.0.0, < 5.4.6
References (6)
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-54467
- https://github.com/neuvector/neuvector/security/advisories/GHSA-w54x-xfxg-4gxq
- https://nvd.nist.gov/vuln/detail/CVE-2025-54467
- https://github.com/neuvector/neuvector
- https://github.com/neuvector/neuvector/commit/f9ddbdf420319cede3c490c1de03f48d953896ae
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54467.json