CVE-2025-59792

Published Nov 28, 2025

Last updated 9 months ago

Overview

Description
Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.
Source
security@apache.org
NVD status
Analyzed
Products
kvrocks

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.3
Impact score
1.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-312

Social media

Hype score
Not currently trending
  1. 108 CVE-2025-58434 CVE-2025-59057 CVE-2025-59343 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-62228 CVE-2025-62232 CVE-2025-64756 CVE-2026-21884 CVE-2026-22706 CVE-2026-22807 CVE-2026-23630 CVE-2026-24015 CVE-2026-24899 CVE-2026-27471 CVE-2026-27806

    @BugBunny_ai

    27 Aug 2026

    4708 Impressions

    0 Retweets

    18 Likes

    6 Bookmarks

    2 Replies

    1 Quote

  2. 66 CVE-2025-58434 CVE-2025-59057 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-64756 CVE-2026-21884 CVE-2026-22807 CVE-2026-23630 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384

    @BugBunny_ai

    14 May 2026

    23006 Impressions

    42 Retweets

    319 Likes

    117 Bookmarks

    12 Replies

    3 Quotes

  3. CVE-2025-59790: Apache Kvrocks: RESET command grants admin privileges https://t.co/LKz6CYYQ48 Severity: critical CVE-2025-59792: Apache Kvrocks: MONITOR command reveals plaintext credentials to non-admins https://t.co/4jcawrDe8i Severity: important

    @oss_security

    4 Dec 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-59792 Plaintext Credential Exposure in Apache Kvrocks MONITOR Command Vulnerability https://t.co/GxXt8cNoTN

    @VulmonFeeds

    28 Nov 2025

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-59792 Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recomm… https://t.co/7v9aUnnYhc

    @CVEnew

    28 Nov 2025

    276 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations