CVE-2025-8415

A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment.
Configurations

No configuration.

History

22 Aug 2025, 18:09

Type Values Removed Values Added
Summary
  • (es) Se detectó una vulnerabilidad en Cryostat HTTP API. Cryostat HTTP API se vincula a todas las interfaces de red, lo que permite visibilidad externa y acceso al puerto de la API si las políticas de red están deshabilitadas, lo que permite que un atacante malicioso no autenticado ponga en peligro el entorno.

20 Aug 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-20 17:15

Updated : 2025-08-22 18:09


NVD link : CVE-2025-8415

Mitre link : CVE-2025-8415

CVE.ORG link : CVE-2025-8415


JSON object : View

Products Affected

No product.

CWE
CWE-289

Authentication Bypass by Alternate Name