Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-8415

Опубликовано: 20 авг. 2025
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment.

Меры по смягчению последствий

Cryostat is not vulnerable by default, as Network Policy is enabled and prevents this behavior. Make sure the Network Policies are enabled in Custom Resources and that the underlying cluster network stack supports Network Policies.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostatAffected
Cryostat 4cryostat/cryostat-operator-bundleAffected
Cryostat 4cryostat/cryostat-rhel9Affected
Cryostat 4cryostat/cryostat-rhel9-operatorAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-289
https://bugzilla.redhat.com/show_bug.cgi?id=2385773cryostat: authentication bypass if Network Policies are disabled

EPSS

Процентиль: 8%
0.00034
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
11 дней назад

A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment.

CVSS3: 5.9
github
11 дней назад

A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment.

EPSS

Процентиль: 8%
0.00034
Низкий

5.9 Medium

CVSS3