CVE-2025-30205 - Kanidim-Provision Admin Credential Leakage Vulnerability

CVE ID : CVE-2025-30205 Published : March 24, 2025, 5:15 p.m. | 1 hour, 59 minutes ago Description : kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to version 1.2.0, a faulty function intrumentation in the (optional) kanidm patches provided by kandim-provision will cause the provisioned admin credentials to be leaked to the system log. This only impacts users which both use the provided patches and provision their `admin` or `idm_admin` account credentials this way. No other credentials are affected. Users should recompile kanidm with the newest patchset from tag `v1.2.0` or higher. As a workaround, the user can set the log level `KANIDM_LOG_LEVEL` to any level higher than `info`, for example `warn`. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Mär 24, 2025 - 20:15
 0  0
CVE-2025-30205 - Kanidim-Provision Admin Credential Leakage Vulnerability
CVE ID : CVE-2025-30205
Published : March 24, 2025, 5:15 p.m. | 1 hour, 59 minutes ago
Description : kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to version 1.2.0, a faulty function intrumentation in the (optional) kanidm patches provided by kandim-provision will cause the provisioned admin credentials to be leaked to the system log. This only impacts users which both use the provided patches and provision their `admin` or `idm_admin` account credentials this way. No other credentials are affected. Users should recompile kanidm with the newest patchset from tag `v1.2.0` or higher. As a workaround, the user can set the log level `KANIDM_LOG_LEVEL` to any level higher than `info`, for example `warn`.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...