Severity
High
Analysis Summary
CVE-2025-59792 CVSS:8.1
Apache Kvrocks could allow a remote authenticated attacker to obtain plaintext credentials information, caused by a flaw in the MONITOR command.
CVE-2025-59790 CVSS:9.1
Apache Kvrocks could allow a local attacker to gain admin privileges on the system, caused by improper privilege management in the RESET command.
Impact
- Information Disclosure
- Privilege Escalation
Indicators of Compromise
CVE
CVE-2025-59792
CVE-2025-59790
Affected Vendors
Apache
Affected Products
- Apache Kvrocks 1.0.0
- Apache Kvrocks 2.13.0
- Apache Kvrocks 2.9.0
- Apache Kvrocks 2.10.0
- Apache Kvrocks 2.11.0
- Apache Kvrocks 2.12.0
Remediation
Upgrade to the latest version of Apache, available from the Apache Website.

