CVE-2025-32435 - Hydra Untrusted Nix Code Secret Access Vulnerability
CVE ID : CVE-2025-32435
Published : April 15, 2025, 11:15 p.m. | 1 hour, 20 minutes ago
Description : Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could potentially access secrets that are accessible by the hydra user/group. This should not affect the signing keys, that are owned by the hydra-queue-runner and hydra-www users respectively.
Severity: 2.6 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 15, 2025, 11:15 p.m. | 1 hour, 20 minutes ago
Description : Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could potentially access secrets that are accessible by the hydra user/group. This should not affect the signing keys, that are owned by the hydra-queue-runner and hydra-www users respectively.
Severity: 2.6 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...