Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges.
Users are advised to upgrade to Amazon EMR version 7.5 or higher. For Amazon EMR releases between 6.10 and 7.4, we strongly recommend that you run the bootstrap script and RPM files with the fix provided in the location below.
Metrics
Affected Vendors & Products
References
History
Fri, 15 Aug 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Amazon
Amazon emr |
|
Vendors & Products |
Amazon
Amazon emr |
Thu, 14 Aug 2025 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 13 Aug 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges. Users are advised to upgrade to Amazon EMR version 7.5 or higher. For Amazon EMR releases between 6.10 and 7.4, we strongly recommend that you run the bootstrap script and RPM files with the fix provided in the location below. | |
Title | Privilege escalation issue in Amazon EMR Secret Agent component | |
Weaknesses | CWE-257 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: AMZN
Published: 2025-08-13T17:06:29.293Z
Updated: 2025-08-15T03:55:55.787Z
Reserved: 2025-08-12T19:43:46.286Z
Link: CVE-2025-8904

Updated: 2025-08-13T20:34:24.881Z

Status : Awaiting Analysis
Published: 2025-08-13T18:15:33.417
Modified: 2025-08-14T13:11:53.633
Link: CVE-2025-8904

No data.