Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.vOnly instances using private helm repositories (i.e setting username & password in the catalogs configuration) are affected. This is fixed in version 4.9.0.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 05 Sep 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.vOnly instances using private helm repositories (i.e setting username & password in the catalogs configuration) are affected. This is fixed in version 4.9.0. | |
Title | Onyxia private helm repository credentials are leaked through unauthenticated API | |
Weaknesses | CWE-522 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-09-05T21:29:46.796Z
Updated: 2025-09-08T20:06:36.035Z
Reserved: 2025-08-29T16:19:59.012Z
Link: CVE-2025-58366

Updated: 2025-09-08T20:06:32.469Z

Status : Awaiting Analysis
Published: 2025-09-05T22:15:34.527
Modified: 2025-09-08T16:25:38.810
Link: CVE-2025-58366

No data.