A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment.
History

Thu, 21 Aug 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 20 Aug 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment.
Title Cryostat: authentication bypass if network policies are disabled
First Time appeared Redhat
Redhat cryostat
Weaknesses CWE-289
CPEs cpe:/a:redhat:cryostat:4
Vendors & Products Redhat
Redhat cryostat
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2025-08-20T16:14:33.566Z

Updated: 2025-08-20T18:43:17.330Z

Reserved: 2025-07-31T13:42:35.044Z

Link: CVE-2025-8415

cve-icon Vulnrichment

Updated: 2025-08-20T18:38:09.247Z

cve-icon NVD

Status : Received

Published: 2025-08-20T17:15:37.953

Modified: 2025-08-20T17:15:37.953

Link: CVE-2025-8415

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-08-20T00:00:00Z

Links: CVE-2025-8415 - Bugzilla