CVE-2025-8904: CWE-257: Storing Passwords in a Recoverable Format in Amazon EMR
Bulletin ID: AWS-2025-017 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/08/13 10:00 PM PDT Description: Amazon EMR is a managed cluster platform that simplifies running big data frameworks on AWS to process and analyze vast amounts of data. We identified CVE-2025-8904, an issue in the Amazon EMR Secret Agent component. The Secret Agent component securely stores secrets and distributes secrets to other Amazon EMR components and applications. When using Amazon EMR clusters with one or more Lake Formation, Apache Ranger, runtime role, or Identity Center feature that uses this component, Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges. We implemented a fix that removes /tmp/ as a staging directory for Kerberos credentials, eliminating the possibility of users accessing the keytab file. The fix is available in Amazon EMR release 7.5 and higher. Affected versions: Amazon EMR version 6.10 through 7.4
AI Analysis
Technical Summary
Amazon EMR versions 6.10 through 7.4 contain a vulnerability (CVE-2025-8904) where the Secret Agent component stores Kerberos credentials in a keytab file in the /tmp/ directory in a recoverable format. This improper storage of sensitive credentials (CWE-257) can allow local users with access to /tmp/ and another account to decrypt the keys, potentially leading to privilege escalation. The vulnerability is rated critical with a CVSS 4.0 score of 9. The vendor recommends upgrading to version 7.5 or later or applying provided bootstrap scripts and RPM fixes to mitigate the issue.
Potential Impact
The vulnerability allows unauthorized users with access to the /tmp/ directory and another account on the same system to decrypt stored Kerberos credentials, which can lead to privilege escalation. This compromises the confidentiality and integrity of authentication credentials within affected Amazon EMR versions, potentially enabling attackers to gain elevated access.
Mitigation Recommendations
A fix is available. Users should upgrade Amazon EMR to version 7.5 or higher. Alternatively, for affected versions, users should apply the vendor-provided bootstrap script and RPM fixes as recommended by Amazon. These actions address the insecure storage of Kerberos credentials and mitigate the risk of privilege escalation.
CVE-2025-8904: CWE-257: Storing Passwords in a Recoverable Format in Amazon EMR
Description
Bulletin ID: AWS-2025-017 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/08/13 10:00 PM PDT Description: Amazon EMR is a managed cluster platform that simplifies running big data frameworks on AWS to process and analyze vast amounts of data. We identified CVE-2025-8904, an issue in the Amazon EMR Secret Agent component. The Secret Agent component securely stores secrets and distributes secrets to other Amazon EMR components and applications. When using Amazon EMR clusters with one or more Lake Formation, Apache Ranger, runtime role, or Identity Center feature that uses this component, Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges. We implemented a fix that removes /tmp/ as a staging directory for Kerberos credentials, eliminating the possibility of users accessing the keytab file. The fix is available in Amazon EMR release 7.5 and higher. Affected versions: Amazon EMR version 6.10 through 7.4
CVSS v4.0
Score 9.0critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Amazon EMR versions 6.10 through 7.4 contain a vulnerability (CVE-2025-8904) where the Secret Agent component stores Kerberos credentials in a keytab file in the /tmp/ directory in a recoverable format. This improper storage of sensitive credentials (CWE-257) can allow local users with access to /tmp/ and another account to decrypt the keys, potentially leading to privilege escalation. The vulnerability is rated critical with a CVSS 4.0 score of 9. The vendor recommends upgrading to version 7.5 or later or applying provided bootstrap scripts and RPM fixes to mitigate the issue.
Potential Impact
The vulnerability allows unauthorized users with access to the /tmp/ directory and another account on the same system to decrypt stored Kerberos credentials, which can lead to privilege escalation. This compromises the confidentiality and integrity of authentication credentials within affected Amazon EMR versions, potentially enabling attackers to gain elevated access.
Mitigation Recommendations
A fix is available. Users should upgrade Amazon EMR to version 7.5 or higher. Alternatively, for affected versions, users should apply the vendor-provided bootstrap script and RPM fixes as recommended by Amazon. These actions address the insecure storage of Kerberos credentials and mitigate the risk of privilege escalation.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- AMZN
- Date Reserved
- 2025-08-12T19:43:46.286Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 689cc8bead5a09ad004f5c94
Added to database: 08/13/2025, 17:17:50 UTC
Last enriched: 06/05/2026, 19:28:39 UTC
Last updated: 08/19/2026, 18:04:43 UTC
Views: 1630
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.