CVE-2025-54882

Source
https://cve.org/CVERecord?id=CVE-2025-54882
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54882.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-54882
Aliases
  • GHSA-phfx-rjfw-wj83
Downstream
Related
Published
2025-08-07T00:02:09.263Z
Modified
2026-04-10T18:44:18.045143171Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Himmelblau's Kerberos credential cache collection is world readable
Details

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.0.0-beta through 1.1.0, Himmelblau stores the cloud TGT received during logon in the Kerberos credential cache. The created credential cache collection and received credentials are stored as world readable. This is fixed in versions 0.9.22 and 1.2.0. To work around this issue, remove all read access to Himmelblau caches for all users except for owners.

Database specific
{
    "cwe_ids": [
        "CWE-522"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54882.json"
}
References

Affected packages

Git / github.com/himmelblau-idm/himmelblau

Affected ranges

Type
GIT
Repo
https://github.com/himmelblau-idm/himmelblau
Events
Database specific
{
    "versions": [
        {
            "introduced": "0.8.0"
        },
        {
            "fixed": "0.9.22"
        }
    ]
}
Type
GIT
Repo
https://github.com/himmelblau-idm/himmelblau
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.0.0-beta"
        },
        {
            "fixed": "1.2.0"
        }
    ]
}

Affected versions

1.*
1.0.0
1.0.0-beta
1.0.0-beta2
1.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54882.json"