216.73.217.22

CVE-2025-10725

· Published 30/09/2025 18:15 · Modified 01/10/2025 09:15

Labels: CVE-2025-10725 2025-09-30CVE-2025-10725CWE-266[email protected]

Essential information

Published
30/09/2025 18:15
Modified
01/10/2025 09:15
Author
Creator
CVSS
9.9 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data scientist using a standard Jupyter notebook, can escalate their privileges to a full cluster administrator. This allows for the complete compromise of the cluster's confidentiality, integrity, and availability. The attacker can steal sensitive data, disrupt all services, and take control of the underlying infrastructure, leading to a total breach of the platform and all applications hosted on it.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
red hat / openshift ai service cpe:2.3:a:red_hat:openshift_ai_service:*:*:*:*:*:*:*:*

References