CVE Vulnerabilities

CVE-2025-28381

Cleartext Storage of Sensitive Information in an Environment Variable

Published: Jun 13, 2025 | Modified: Jun 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A credential leak in OpenC3 COSMOS v6.0.0 allows attackers to access service credentials as environment variables stored in all containers.

Weakness

The product uses an environment variable to store unencrypted sensitive information.

Affected Software

Name Vendor Start Version End Version
Cosmos Openc3 6.0.0 (including) 6.0.0 (including)

Potential Mitigations

References