Junglewise Threat Intelligence

CVE-2025-54467: SUSE NeuVector sensitive information disclosure in security event logs

CVE-2025-54467 · Severity: medium · CVSS 5.3 · Published 2025-08-28

Technologies: Suse NeuVector, github.com/neuvector/neuvector (Go). Vendors: Suse, Go.

Executive brief

NeuVector, a container security platform, may inadvertently record sensitive information like passwords in its security event logs. This occurs when a process (such as a Java application) is terminated for a rule violation and its command-line arguments contain credentials that do not match the platform's default redaction filters. If an unauthorized person gains access to these logs, they could obtain sensitive credentials, potentially leading to further unauthorized access to the environment.

Technical details

NeuVector is vulnerable to information disclosure (CWE-522, CWE-549) because it may fail to redact sensitive credentials from process command-line arguments in security event logs. When the NeuVector enforcer terminates a process for a rule violation, it logs the full command; if the command contains passwords or tokens that fall outside the default regex pattern `(?i)(password|passwd|token)`, these secrets are stored in plain text. While users can add custom patterns via a Kubernetes ConfigMap, doing so extensively can cause performance degradation due to regex backtracking. The vulnerability is reachable over the network if an attacker can trigger process violations or view security events. The issue is resolved in NeuVector version 5.4.6.

Affected products

  • SUSE NeuVector < 5.4.6

Timeline

  • 2025-08-26: disclosed
  • 2025-08-28: advisory
  • 2025-08-28: patched: Fixed in version 5.4.6

References

Related threats