Executive brief
NeuVector, a container security platform, was found to store user passwords and API keys using insecure, unsalted hashes. If an attacker gains access to the underlying database, they could use precomputed tables to quickly crack these passwords and keys. This could lead to unauthorized access to the security management console and sensitive cloud infrastructure.
Technical details
NeuVector was identified as using insecure password storage (CWE-759, CWE-916) by utilizing unsalted hashes for user credentials and API keys. This lack of salting allows for efficient offline cracking using rainbow tables if the hash data is exfiltrated. The vulnerability is addressed in version 5.4.6 by implementing PBKDF2 with a cryptographically secure 16-character salt. Post-patch, users must re-authenticate and API keys must be used at least once to trigger the regeneration of hashes using the new secure method.
Affected products
- SUSE NeuVector < 5.4.6
Timeline
- 2025-08-26: disclosed
- 2025-08-28: advisory