Junglewise Threat Intelligence

CVE-2025-51055: Vedo Suite Project Vedo Suite cleartext storage of credentials in config.yml

CVE-2025-51055 · Severity: high · CVSS 8.6 · Published 2025-08-06

Technologies: Vedo Suite Project Vedo Suite. Vendors: Vedo Suite Project.

Executive brief

A security vulnerability has been identified in Vedo Suite version 2024.17, a software suite used for data management and monitoring. A configuration file is stored in a way that allows sensitive information, including administrative passwords, secret keys, and database connection details, to be accessed in plain text. An attacker could use this information to gain unauthorized access to the system, compromise customer data, or take control of the underlying database.

Technical details

A Cleartext Storage of Sensitive Information vulnerability (CWE-312) exists in Vedo Suite version 2024.17. The vulnerability is located in the '/api_vedo/configuration/config.yml' file, which contains sensitive configuration data in an unencrypted format. A remote, unauthenticated attacker can access this file over the network to retrieve clear-text credentials, cryptographic secret keys, and database connection strings. This exposure provides a direct path for full system compromise or unauthorized database access. Proof-of-concept exploits have been identified in public repositories.

Affected products

  • Vedo Suite Project Vedo Suite 2024.17

Timeline

  • 2025-08-06: advisory: Initial disclosure of CVE-2025-51055
  • 2025-08-07: other: CISA-ADP enrichment and CVSS scoring added

References

Related threats