An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cluster admin/user, who has standard user access to the cluster, and the Red Hat Developer Hub namespace, can access the rhdh/rhdh-hub-rhel9 container image and modify the image's content. This issue affects the confidentiality and integrity of the data, and any changes made are not permanent, as they reset after the pod restarts.
History

Tue, 19 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 19 Aug 2025 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:rhdh:1 cpe:/a:redhat:rhdh:1.7::el9
References

Tue, 19 Aug 2025 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 19 Aug 2025 04:45:00 +0000

Type Values Removed Values Added
Description An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cluster admin/user, who has standard user access to the cluster, and the Red Hat Developer Hub namespace, can access the rhdh/rhdh-hub-rhel9 container image and modify the image's content. This issue affects the confidentiality and integrity of the data, and any changes made are not permanent, as they reset after the pod restarts.
Title Rhdh: red hat developer hub user permissions
First Time appeared Redhat
Redhat rhdh
Weaknesses CWE-266
CPEs cpe:/a:redhat:rhdh:1
Vendors & Products Redhat
Redhat rhdh
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2025-08-19T04:28:08.316Z

Updated: 2025-08-20T16:29:11.634Z

Reserved: 2025-05-31T22:36:52.134Z

Link: CVE-2025-5417

cve-icon Vulnrichment

Updated: 2025-08-19T19:21:20.054Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-19T05:15:29.733

Modified: 2025-08-19T16:15:29.083

Link: CVE-2025-5417

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-08-19T00:00:00Z

Links: CVE-2025-5417 - Bugzilla