CVE-2025-11393: Unintended Proxy or Intermediary ('Confused Deputy') in Red Hat Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user within the cluster to send unauthorized commands to the management platform, effectively acting with the full permissions of the cluster administrator. This could lead to unauthorized changes to the cluster's configuration or status on the Red Hat platform.
AI Analysis
Technical Summary
CVE-2025-11393 is a vulnerability in the runtimes-inventory-rhel8-operator component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0.0. The vulnerability arises from an internal proxy component that is incorrectly configured, causing it to attach the cluster's main administrative credentials to any command it receives rather than limiting credentials to specific reports. This misconfiguration allows a standard user within the cluster to send unauthorized commands to the management platform, effectively gaining full administrative privileges over the cluster. The vulnerability has a CVSS 3.1 base score of 8.7 (high severity) with an attack vector of adjacent network, low attack complexity, low privileges required, no user interaction, and a changed scope. Red Hat has issued updated RHEL 9 container images containing backported patches to fix this issue and recommends users upgrade and rebuild dependent container images. As a temporary mitigation, disabling the proxy server by setting INSIGHTS_ENABLED to false is possible, though it causes a crash loop in the Insights container, which is harmless. No active exploitation has been reported. The vulnerability is tracked under Red Hat advisory RHSA-2025:23236.
Potential Impact
An attacker with standard user privileges within the cluster can exploit this vulnerability to execute commands with the full permissions of the cluster administrator on the Red Hat management platform. This could lead to unauthorized changes to the cluster's configuration or status, potentially compromising cluster integrity and control. The vulnerability does not impact availability but has high confidentiality and integrity impacts.
Mitigation Recommendations
Red Hat has released updated RHEL 9 container images with backported patches that fix this vulnerability. Users of Red Hat Insights for Runtimes on RHEL 8 container images are advised to upgrade to these updated images and rebuild all dependent container images. As a temporary mitigation, the proxy server can be disabled by adding the environment variable INSIGHTS_ENABLED set to "false" in the Cryostat or JWS subscription YAML. This disables the affected proxy but causes a harmless crash loop in the Insights container. Users should apply all previously released errata relevant to their system before updating. Refer to Red Hat advisory RHSA-2025:23236 for detailed update instructions.
CVE-2025-11393: Unintended Proxy or Intermediary ('Confused Deputy') in Red Hat Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
Description
A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user within the cluster to send unauthorized commands to the management platform, effectively acting with the full permissions of the cluster administrator. This could lead to unauthorized changes to the cluster's configuration or status on the Red Hat platform.
CVSS v3.1
Score 8.7high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-11393 is a vulnerability in the runtimes-inventory-rhel8-operator component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0.0. The vulnerability arises from an internal proxy component that is incorrectly configured, causing it to attach the cluster's main administrative credentials to any command it receives rather than limiting credentials to specific reports. This misconfiguration allows a standard user within the cluster to send unauthorized commands to the management platform, effectively gaining full administrative privileges over the cluster. The vulnerability has a CVSS 3.1 base score of 8.7 (high severity) with an attack vector of adjacent network, low attack complexity, low privileges required, no user interaction, and a changed scope. Red Hat has issued updated RHEL 9 container images containing backported patches to fix this issue and recommends users upgrade and rebuild dependent container images. As a temporary mitigation, disabling the proxy server by setting INSIGHTS_ENABLED to false is possible, though it causes a crash loop in the Insights container, which is harmless. No active exploitation has been reported. The vulnerability is tracked under Red Hat advisory RHSA-2025:23236.
Potential Impact
An attacker with standard user privileges within the cluster can exploit this vulnerability to execute commands with the full permissions of the cluster administrator on the Red Hat management platform. This could lead to unauthorized changes to the cluster's configuration or status, potentially compromising cluster integrity and control. The vulnerability does not impact availability but has high confidentiality and integrity impacts.
Mitigation Recommendations
Red Hat has released updated RHEL 9 container images with backported patches that fix this vulnerability. Users of Red Hat Insights for Runtimes on RHEL 8 container images are advised to upgrade to these updated images and rebuild all dependent container images. As a temporary mitigation, the proxy server can be disabled by adding the environment variable INSIGHTS_ENABLED set to "false" in the Cryostat or JWS subscription YAML. This disables the affected proxy but causes a harmless crash loop in the Insights container. Users should apply all previously released errata relevant to their system before updating. Refer to Red Hat advisory RHSA-2025:23236 for detailed update instructions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2025-10-07T02:24:57.427Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2025:23236","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2025-11393","vendor":"Red Hat"}]
Threat ID: 69404222d9bcdf3f3df0a13a
Added to database: 12/15/2025, 17:15:14 UTC
Last enriched: 08/13/2026, 16:42:54 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 391
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.