CVE-2024-52284
Severity CVSS v4.0:
Pending analysis
Type:
CWE-312
Cleartext Storage of Sensitive Information
Publication date:
02/09/2025
Last modified:
02/09/2025
Description
Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets.
Impact
Base Score 3.x
7.70
Severity 3.x
HIGH



