CVE-2025-36154

IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.
References
Link Resource
https://www.ibm.com/support/pages/node/7255549 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:concert:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-24 19:15

Updated : 2025-12-30 20:35


NVD link : CVE-2025-36154

Mitre link : CVE-2025-36154

CVE.ORG link : CVE-2025-36154


JSON object : View

Products Affected

ibm

  • concert
CWE
CWE-313

Cleartext Storage in a File or on Disk