CVE Vulnerabilities

CVE-2025-28381

Cleartext Storage of Sensitive Information in an Environment Variable

Published: Jun 13, 2025 | Modified: Oct 27, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.

Weakness

The product uses an environment variable to store unencrypted sensitive information.

Affected Software

NameVendorStart VersionEnd Version
CosmosOpenc36.0.0 (including)6.0.0 (including)

Potential Mitigations

References