kanidm-provision Admin Credential Logging Vulnerability

Vulnerability

A vulnerability in kanidm-provision versions prior to 1.2.0 allows provisioned admin credentials to be leaked into the system log. This issue arises from a faulty function instrumentation in the optional kanidm patches provided by kanidm-provision. The vulnerability only affects users who utilize these patches and provision their admin or idm_admin account credentials in this manner. Other credentials remain unaffected.

Impact

Exploitation of this vulnerability leads to the unintentional logging of admin credentials, which could be accessed by unauthorized users or processes with the ability to read the system log.

Remediation

Users should recompile kanidm with the latest patchset from tag v1.2.0 or higher. As a temporary workaround, set the log level KANIDM_LOG_LEVEL to any level higher than info, such as warn.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.5
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.