All the vulnerabilites related to Red Hat - Cryostat 4
cve-2025-8415
Vulnerability from cvelistv5
Published
2025-08-20 16:14
Modified
2025-09-03 03:05
Severity ?
EPSS score ?
Summary
Cryostat: authentication bypass if network policies are disabled
References
▼ | URL | Tags |
---|---|---|
https://access.redhat.com/errata/RHSA-2025:14919 | vendor-advisory, x_refsource_REDHAT | |
https://access.redhat.com/security/cve/CVE-2025-8415 | vdb-entry, x_refsource_REDHAT | |
https://bugzilla.redhat.com/show_bug.cgi?id=2385773 | issue-tracking, x_refsource_REDHAT |
Impacted products
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-8415", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-08-20T18:43:09.674363Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-08-20T18:43:17.330Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "collectionURL": "https://catalog.redhat.com/software/containers/", "cpes": [ "cpe:/a:redhat:cryostat:4::el9" ], "defaultStatus": "affected", "packageName": "cryostat/cryostat-agent-init-rhel9", "product": "Cryostat 4 on RHEL 9", "vendor": "Red Hat", "versions": [ { "lessThan": "*", "status": "unaffected", "version": "0.5.2-3", "versionType": "rpm" } ] }, { "collectionURL": "https://catalog.redhat.com/software/containers/", "cpes": [ "cpe:/a:redhat:cryostat:4::el9" ], "defaultStatus": "affected", "packageName": "cryostat/cryostat-db-rhel9", "product": "Cryostat 4 on RHEL 9", "vendor": "Red Hat", "versions": [ { "lessThan": "*", "status": "unaffected", "version": "4.0.2-3", "versionType": "rpm" } ] }, { "collectionURL": "https://catalog.redhat.com/software/containers/", "cpes": [ "cpe:/a:redhat:cryostat:4::el9" ], "defaultStatus": "affected", "packageName": "cryostat/cryostat-grafana-dashboard-rhel9", "product": "Cryostat 4 on RHEL 9", "vendor": "Red Hat", "versions": [ { "lessThan": "*", "status": "unaffected", "version": "4.0.2-3", "versionType": "rpm" } ] }, { "collectionURL": "https://catalog.redhat.com/software/containers/", "cpes": [ "cpe:/a:redhat:cryostat:4::el9" ], "defaultStatus": "affected", "packageName": "cryostat/cryostat-openshift-console-plugin-rhel9", "product": "Cryostat 4 on RHEL 9", "vendor": "Red Hat", "versions": [ { "lessThan": "*", "status": "unaffected", "version": "4.0.2-3", "versionType": "rpm" } ] }, { "collectionURL": "https://catalog.redhat.com/software/containers/", "cpes": [ "cpe:/a:redhat:cryostat:4::el9" ], "defaultStatus": "affected", "packageName": "cryostat/cryostat-operator-bundle", "product": "Cryostat 4 on RHEL 9", "vendor": "Red Hat", "versions": [ { "lessThan": "*", "status": "unaffected", "version": "4.0.2-3", "versionType": "rpm" } ] }, { "collectionURL": "https://catalog.redhat.com/software/containers/", "cpes": [ "cpe:/a:redhat:cryostat:4::el9" ], "defaultStatus": "affected", "packageName": "cryostat/cryostat-ose-oauth-proxy-rhel9", "product": "Cryostat 4 on RHEL 9", "vendor": "Red Hat", "versions": [ { "lessThan": "*", "status": "unaffected", "version": "4.0.2-3", "versionType": "rpm" } ] }, { "collectionURL": "https://catalog.redhat.com/software/containers/", "cpes": [ "cpe:/a:redhat:cryostat:4::el9" ], "defaultStatus": "affected", "packageName": "cryostat/cryostat-reports-rhel9", "product": "Cryostat 4 on RHEL 9", "vendor": "Red Hat", "versions": [ { "lessThan": "*", "status": "unaffected", "version": "4.0.2-3", "versionType": "rpm" } ] }, { "collectionURL": "https://catalog.redhat.com/software/containers/", "cpes": [ "cpe:/a:redhat:cryostat:4::el9" ], "defaultStatus": "affected", "packageName": "cryostat/cryostat-rhel9", "product": "Cryostat 4 on RHEL 9", "vendor": "Red Hat", "versions": [ { "lessThan": "*", "status": "unaffected", "version": "4.0.2-3", "versionType": "rpm" } ] }, { "collectionURL": "https://catalog.redhat.com/software/containers/", "cpes": [ "cpe:/a:redhat:cryostat:4::el9" ], "defaultStatus": "affected", "packageName": "cryostat/cryostat-rhel9-operator", "product": "Cryostat 4 on RHEL 9", "vendor": "Red Hat", "versions": [ { "lessThan": "*", "status": "unaffected", "version": "4.0.2-3", "versionType": "rpm" } ] }, { "collectionURL": "https://catalog.redhat.com/software/containers/", "cpes": [ "cpe:/a:redhat:cryostat:4::el9" ], "defaultStatus": "affected", "packageName": "cryostat/cryostat-storage-rhel9", "product": "Cryostat 4 on RHEL 9", "vendor": "Red Hat", "versions": [ { "lessThan": "*", "status": "unaffected", "version": "4.0.2-3", "versionType": "rpm" } ] }, { "collectionURL": "https://catalog.redhat.com/software/containers/", "cpes": [ "cpe:/a:redhat:cryostat:4::el9" ], "defaultStatus": "affected", "packageName": "cryostat/jfr-datasource-rhel9", "product": "Cryostat 4 on RHEL 9", "vendor": "Red Hat", "versions": [ { "lessThan": "*", "status": "unaffected", "version": "4.0.2-3", "versionType": "rpm" } ] }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/a:redhat:cryostat:4" ], "defaultStatus": "affected", "packageName": "cryostat", "product": "Cryostat 4", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/a:redhat:cryostat:4" ], "defaultStatus": "affected", "packageName": "cryostat/cryostat-rhel9", "product": "Cryostat 4", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/a:redhat:cryostat:4" ], "defaultStatus": "affected", "packageName": "cryostat/cryostat-rhel9-operator", "product": "Cryostat 4", "vendor": "Red Hat" } ], "datePublic": "2025-08-20T00:00:00.000Z", "descriptions": [ { "lang": "en", "value": "A vulnerability was found in the Cryostat HTTP API. Cryostat\u0027s HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment." } ], "metrics": [ { "other": { "content": { "namespace": "https://access.redhat.com/security/updates/classification/", "value": "Moderate" }, "type": "Red Hat severity rating" } }, { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.9, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "HIGH", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N", "version": "3.1" }, "format": "CVSS" } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-289", "description": "Authentication Bypass by Alternate Name", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-03T03:05:41.550Z", "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat" }, "references": [ { "name": "RHSA-2025:14919", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ], "url": "https://access.redhat.com/errata/RHSA-2025:14919" }, { "tags": [ "vdb-entry", "x_refsource_REDHAT" ], "url": "https://access.redhat.com/security/cve/CVE-2025-8415" }, { "name": "RHBZ#2385773", "tags": [ "issue-tracking", "x_refsource_REDHAT" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2385773" } ], "timeline": [ { "lang": "en", "time": "2025-07-31T13:30:18.157000+00:00", "value": "Reported to Red Hat." }, { "lang": "en", "time": "2025-08-20T00:00:00+00:00", "value": "Made public." } ], "title": "Cryostat: authentication bypass if network policies are disabled", "workarounds": [ { "lang": "en", "value": "Cryostat is not vulnerable by default, as Network Policy is enabled and prevents this behavior. Make sure the Network Policies are enabled in Custom Resources and that the underlying cluster network stack supports Network Policies." } ], "x_redhatCweChain": "CWE-289: Authentication Bypass by Alternate Name" } }, "cveMetadata": { "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "assignerShortName": "redhat", "cveId": "CVE-2025-8415", "datePublished": "2025-08-20T16:14:33.566Z", "dateReserved": "2025-07-31T13:42:35.044Z", "dateUpdated": "2025-09-03T03:05:41.550Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }