{"id":"CVE-2025-14758","summary":"Initialization of a Resource with an Insecure Default in YAOOK","details":"Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows an on-path attacker to read database contents, potentially including credentials","modified":"2026-08-12T03:51:33.662364408Z","published":"2025-12-16T00:33:32.971Z","database_specific":{"cwe_ids":["CWE-1188"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14758.json","cna_assigner":"GitLab"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14758.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14758"},{"type":"REPORT","url":"https://gitlab.com/yaook/operator/-/issues/631"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/yaook/operator","events":[{"introduced":"2e427dcb0a9c4759ae4548c97df4d5f40737da62"},{"fixed":"5544d2cda04a43fec24880eead35f773ef7ad59a"}],"database_specific":{"extracted_events":[{"introduced":"0.20240809.0"},{"fixed":"0.20251211.0"}],"source":"AFFECTED_FIELD"}}],"versions":["0.20251208.1","0.20251127.0","0.20251117.1","0.20251103.0","0.20251023.0","0.20250918.0","0.20250904.0","0.20250724.0","0.20250717.0","0.20250710.0","0.20250703.1","0.20250626.2","0.20250624.0","0.20250612.0","0.20250605.2","0.20250602.0","0.20250512.1","0.20250507.0","0.20250429.0","0.20250324.1","0.20250227.0","0.20250213.1","0.20250206.1","0.20250127.0","0.20250121.0","0.20250108.0","0.20241205.2","0.20241021.0","0.20240919.2","0.20240809.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14758.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}