A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Wed, 20 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 20 Aug 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment. | |
Title | Cryostat: authentication bypass if network policies are disabled | |
First Time appeared |
Redhat
Redhat cryostat |
|
Weaknesses | CWE-289 | |
CPEs | cpe:/a:redhat:cryostat:4 | |
Vendors & Products |
Redhat
Redhat cryostat |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published: 2025-08-20T16:14:33.566Z
Updated: 2025-08-20T18:43:17.330Z
Reserved: 2025-07-31T13:42:35.044Z
Link: CVE-2025-8415

Updated: 2025-08-20T18:38:09.247Z

Status : Received
Published: 2025-08-20T17:15:37.953
Modified: 2025-08-20T17:15:37.953
Link: CVE-2025-8415
