Junglewise Threat Intelligence

CVE-2025-46808: SUSE NeuVector Manager sensitive information insertion into logs

CVE-2025-46808 · Severity: medium · CVSS 6.8 · Published 2026-09-09

Vendors: Suse.

Executive brief

SUSE NeuVector Manager is a container security platform used to monitor and protect containerized workloads. A vulnerability in versions before 5.4.5 allows sensitive credentials—including authentication tokens, API keys, and cryptographic keys—to be written to the manager container's log files. If logs are collected by external systems without proper access controls, attackers with log access could obtain credentials to compromise the system and connected infrastructure.

Technical details

This is a sensitive information insertion vulnerability (CWE-532) affecting NeuVector Manager before version 5.4.5. The vulnerability occurs when the manager logs request/response data without filtering, exposing credentials such as Rancher SSO tokens (X-R-Sess), GitHub/Azure DevOps personal access tokens, NeuVector session tokens, and Sigstore cryptographic keys. The attack requires low privileges and user interaction (e.g., logging in via Rancher SSO or submitting configuration), and is network-reachable. The impact depends on logging strategy: local logging limits exposure, but external log aggregation systems without proper access controls significantly increase risk. Patch version 5.4.5 and later mask or remove sensitive fields from logs, and users are advised to rotate GitHub tokens after upgrading.

Affected products

  • SUSE NeuVector Manager before 5.4.5

Timeline

  • 2025-07-11: disclosed: GHSA-fggw-hv56-8m6r published
  • 2025-05-XX: patched: Version 5.4.5 released with fix
  • 2026-09-09: advisory: CVE-2025-46808 published on NVD

References