VDB
RHSA-2025%3A2754
RHSA-2025%3A2754
PUBLISHED
CVSS 7.400000095367432 HIGH
A flaw was found in OpenSSL's RFC7250 Raw Public Key (RPK) authentication. This vulnerability allows man-in-the-middle (MITM) attacks via failure to abort TLS/DTLS handshakes when the server's RPK does not match the expected key despite the SSL_VERIFY_PEER verification mode being set.
Risk Scores
CVSS 3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-waiters-rhel9@sha256:1f83f221073a446831be632825290ac124552d26594aa0aff17be2c913586da9_arm64 as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-waiters-rhel9@sha256:1f83f221073a446831be632825290ac124552d26594aa0aff17be2c913586da9_arm64 |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:a5c01b08b53d8efb0865dcc73538f5f4b82d6f535661d7d3870c45793960fa7d_s390x as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:a5c01b08b53d8efb0865dcc73538f5f4b82d6f535661d7d3870c45793960fa7d_s390x |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:ac054977db4a4c6d404582cda6b83ab56ddda02a08394547536c31cd2d3dce87_amd64 as a component of Builds for Red Hat OpenShift 1.3.2 | * |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:8bb5f5d121a135ddd3c3038167b2bed668efe4f2d2c69a6e7e1bb5671c9e3043_ppc64le as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:8bb5f5d121a135ddd3c3038167b2bed668efe4f2d2c69a6e7e1bb5671c9e3043_ppc64le |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-webhook-rhel9@sha256:53dc5c92561e1fd614af9419a638e07ee1a6d5f7313a8e783c9b2dcf77b728ca_s390x as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-webhook-rhel9@sha256:53dc5c92561e1fd614af9419a638e07ee1a6d5f7313a8e783c9b2dcf77b728ca_s390x |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:748a1949915fe211bd9ee4af457dd228f189948e3d8a5a8a52255f7a8ee98931_arm64 as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:748a1949915fe211bd9ee4af457dd228f189948e3d8a5a8a52255f7a8ee98931_arm64 |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:e5fd134b163486b3e0ae6683668acfe146d3c05a4cb9fd4b4e280ae429fbf7c7_amd64 as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:e5fd134b163486b3e0ae6683668acfe146d3c05a4cb9fd4b4e280ae429fbf7c7_amd64 |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:02d0ae03cf0122360b8dac54467295bfd4a97ea32471bc9b524bca437eaf61ee_s390x as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:02d0ae03cf0122360b8dac54467295bfd4a97ea32471bc9b524bca437eaf61ee_s390x |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-webhook-rhel9@sha256:d957bd56b672c24da12c949aa63b13cb7858f867ec76854a3cdf6e334021b9fd_amd64 as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-webhook-rhel9@sha256:d957bd56b672c24da12c949aa63b13cb7858f867ec76854a3cdf6e334021b9fd_amd64 |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-operator-bundle@sha256:7a6ef43322827fe9e35d1c907eb02fd05a7b5ad370d85c93a32e0454bb7aa322_ppc64le as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-operator-bundle@sha256:7a6ef43322827fe9e35d1c907eb02fd05a7b5ad370d85c93a32e0454bb7aa322_ppc64le |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:80dd2052f12f08d9c7fe07113a7b3e6fa2bbb559bbce6ea828cd826f722eee37_amd64 as a component of Builds for Red Hat OpenShift 1.3.2 | * |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:9a178523f8537a5c3e66b320e15370f01d74702f45eca46f3a34c937518f40a0_arm64 as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:9a178523f8537a5c3e66b320e15370f01d74702f45eca46f3a34c937518f40a0_arm64 |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:a63d86f558e51e6233b4c5262311602f50c34b16154741f1062a598d67f4c0d7_arm64 as a component of Builds for Red Hat OpenShift 1.3.2 | * |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:06780cf9d827b4e3c111e32d983db02d13e740817a09bcf281d1ffd3c225cdf8_s390x as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:06780cf9d827b4e3c111e32d983db02d13e740817a09bcf281d1ffd3c225cdf8_s390x |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:be45a37a6a4b5685af69e426ffae4601b2bf087336bd30b3667fbc6da0014ac4_amd64 as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:be45a37a6a4b5685af69e426ffae4601b2bf087336bd30b3667fbc6da0014ac4_amd64 |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-waiters-rhel9@sha256:b702dfbbaac18f8ff318c870dff0ab45aac1245a466f800ea243710f44d1c0c7_s390x as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-waiters-rhel9@sha256:b702dfbbaac18f8ff318c870dff0ab45aac1245a466f800ea243710f44d1c0c7_s390x |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:8908e3b99a75e5e0936426f52c0e71c76fdc44c1a229298bc7b0fec53ea372ac_ppc64le as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:8908e3b99a75e5e0936426f52c0e71c76fdc44c1a229298bc7b0fec53ea372ac_ppc64le |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-webhook-rhel9@sha256:2cd8a9407bb0aa19f72a6e22ff75ca60157d855fac081c1bcf464db56ebe56e2_ppc64le as a component of Builds for Red Hat OpenShift 1.3.2 | * |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:628167b3348b5baa7e83b8c70998dd57618153d53883018fa58f3720093b46b3_amd64 as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:628167b3348b5baa7e83b8c70998dd57618153d53883018fa58f3720093b46b3_amd64 |
| Red Hat | registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:eb70675111930268da24ba834045532d133a399774cb24244b36ea11e52dec21_s390x as a component of Builds for Red Hat OpenShift 1.3.2 | registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:eb70675111930268da24ba834045532d133a399774cb24244b36ea11e52dec21_s390x |
…and 20 more
Timeline
- Mar 13, 2025 CVE Published
- Mar 31, 2026 PoC Published
- Apr 24, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:2754 advisory
- https://docs.openshift.com/builds/1.1/about/overview-openshift-builds.html advisory
- https://access.redhat.com/security/cve/CVE-2024-12797 advisory
- https://access.redhat.com/security/cve/CVE-2025-1244 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_2754.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2342757 issue
- https://www.cve.org/CVERecord?id=CVE-2024-12797 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-12797 advisory
- https://openssl-library.org/news/secadv/20250211.txt advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2345150 issue
- https://www.cve.org/CVERecord?id=CVE-2025-1244 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-1244 advisory