CVE-2025-8415 Details
Description
A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment.
An authentication bypass vulnerability has been identified in the Cryostat HTTP API, specifically in version 4.0.0. The API binds to all network interfaces, which can expose the API port to external access if Network Policies are disabled. This vulnerability allows an unauthenticated, malicious attacker to send HTTP requests directly to the Cryostat API, bypassing the OpenShift OAuth authentication and authorization mechanisms. The issue arises when the underlying cluster network stack does not support Network Policies, or if the Cryostat installation has been configured to disable them.
Ensure that Network Policies are enabled in the Cryostat Custom Resources and that the underlying cluster network stack supports Network Policies. If Network Policies are disabled, re-enable them or adjust the Cryostat installation to restore the default Network Policy settings.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 20, 2025CISA-ADP
Assessed Aug 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-289 | Authentication Bypass by Alternate Name | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Red Hat Cryostat | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 23, 2025 | CVE Modified | [email protected] |
| Sep 3, 2025 | CVE Modified | [email protected] |
| Aug 20, 2025 | New CVE Received | [email protected] |
Volerion