Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25390 | A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment. |
Solution
No solution given by the vendor.
Workaround
Cryostat is not vulnerable by default, as Network Policy is enabled and prevents this behavior. Make sure the Network Policies are enabled in Custom Resources and that the underlying cluster network stack supports Network Policies.
Wed, 03 Sep 2025 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:cryostat:4::el9 | |
| References |
|
Thu, 21 Aug 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 20 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment. | |
| Title | Cryostat: authentication bypass if network policies are disabled | |
| First Time appeared |
Redhat
Redhat cryostat |
|
| Weaknesses | CWE-289 | |
| CPEs | cpe:/a:redhat:cryostat:4 | |
| Vendors & Products |
Redhat
Redhat cryostat |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-09-03T03:05:41.550Z
Reserved: 2025-07-31T13:42:35.044Z
Link: CVE-2025-8415
Updated: 2025-08-20T18:38:09.247Z
Status : Awaiting Analysis
Published: 2025-08-20T17:15:37.953
Modified: 2025-09-03T04:16:06.033
Link: CVE-2025-8415
OpenCVE Enrichment
No data.
EUVD