CVE-2025-67745
MyHoard is a daemon for creating, managing and restoring MySQL backups. Starting in version 1.0.1 and prior to version 1.3.0, in some cases, myhoard logs the whole backup info, including the encryption key. Version 1.3.0 fixes the issue. As a workaround, direct logs into /dev/null.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- EPSS probability
- 0.15%
- CWE
- CWE-402
- Published
- 2025-12-18
- Last modified
- 2026-03-13
Affected products
- Aiven-Open myhoard
Weakness type
Related vulnerabilities
- CVE-2025-66422 — Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup)...
- CVE-2025-55014 — The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and...
- CVE-2025-49618 — In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId,...
- CVE-2025-52925 — In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken...
- CVE-2025-48383 — Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
- CVE-2025-32360 — In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and...
- CVE-2025-29925 — XWiki allows unregistered users to access private pages information through REST endpoint
- CVE-2025-0502 — Transmission of Private Resources into a New Sphere in Crafter Engine