An insufficient access control vulnerability was found in the Red Hat
Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cluster admin/user, who has standard user access to the cluster, and the Red Hat Developer Hub namespace, can access the
rhdh/rhdh-hub-rhel9 container image and modify the image's content. This issue affects the confidentiality and integrity of the data, and any changes made are not permanent, as they reset after the pod restarts.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 Aug 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:rhdh:1.7::el9 | |
| References |
|
Tue, 19 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 19 Aug 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cluster admin/user, who has standard user access to the cluster, and the Red Hat Developer Hub namespace, can access the rhdh/rhdh-hub-rhel9 container image and modify the image's content. This issue affects the confidentiality and integrity of the data, and any changes made are not permanent, as they reset after the pod restarts. | |
| Title | Rhdh: red hat developer hub user permissions | |
| First Time appeared |
Redhat
Redhat rhdh |
|
| Weaknesses | CWE-266 | |
| CPEs | cpe:/a:redhat:rhdh:1 | |
| Vendors & Products |
Redhat
Redhat rhdh |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2025-08-19T04:28:08.316Z
Updated: 2025-10-03T21:36:29.136Z
Reserved: 2025-05-31T22:36:52.134Z
Link: CVE-2025-5417
Updated: 2025-08-19T19:21:20.054Z
Status : Awaiting Analysis
Published: 2025-08-19T05:15:29.733
Modified: 2025-08-19T16:15:29.083
Link: CVE-2025-5417