Aller au contenu

Fiche vulnérabilité

CVE-2025-66411 : faille moyenne coder coder (CVSS 5.5)

Description

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized. An attacker with limited local access to the Coder Workspace (VM, K8s Pod etc.) or a third-party system (SIEM, logging stack) could access those logs. This vulnerability is fixed in 2.26.5, 2.27.7, and 2.28.4.

En bref

Sévérité
Moyenne (CVSS 5.5)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
3 déc. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • coder coder

Références

Rechercher une autre vulnérabilité dans la base CVE