CVE-2025-8415 PUBLISHED CVSS 5.900000095367432 MEDIUM

A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment.

EPSS 0.04% · 10.6th percentile

Risk Scores

CVSS v3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.04%
10.6th percentile

Affected Products

VendorProductVersions
Red HatCryostat 4 on RHEL 94.0.2-3
Red HatCryostat 4 on RHEL 94.0.2-3
Red HatCryostat 4 on RHEL 94.0.2-3
Red HatCryostat 4 on RHEL 94.0.2-3
Red HatCryostat 4
Red HatCryostat 4 on RHEL 94.0.2-3
CryostatCryostat0
Red HatCryostat 4
Red HatCryostat 4 on RHEL 94.0.2-3
Red HatCryostat 4 on RHEL 94.0.2-3
Red HatCryostat 4
Red HatCryostat 4 on RHEL 90.5.2-3
Red HatCryostat 4 on RHEL 94.0.2-3
Red HatCryostat 4 on RHEL 94.0.2-3
Red HatCryostat 4 on RHEL 94.0.2-3

Timeline

References

Open in Interactive Console →