Skip to main content
EPSS 0.2%top 91%

CVE-2025-11393: Unintended Proxy or Intermediary ('Confused Deputy') in Red Hat Red Hat Lightspeed (formerly Insights) for Runtimes 1.0

0
High
VulnerabilityCVE-2025-11393cvecve-2025-11393
Published: 12/15/2025 (12/15/2025, 17:03:44 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat Lightspeed (formerly Insights) for Runtimes 1.0

Description

A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user within the cluster to send unauthorized commands to the management platform, effectively acting with the full permissions of the cluster administrator. This could lead to unauthorized changes to the cluster's configuration or status on the Red Hat platform.

CVSS v3.1

Score 8.7high

Attack Vector
Adjacent Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 16:42:54 UTC

Technical Analysis

CVE-2025-11393 is a vulnerability in the runtimes-inventory-rhel8-operator component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0.0. The vulnerability arises from an internal proxy component that is incorrectly configured, causing it to attach the cluster's main administrative credentials to any command it receives rather than limiting credentials to specific reports. This misconfiguration allows a standard user within the cluster to send unauthorized commands to the management platform, effectively gaining full administrative privileges over the cluster. The vulnerability has a CVSS 3.1 base score of 8.7 (high severity) with an attack vector of adjacent network, low attack complexity, low privileges required, no user interaction, and a changed scope. Red Hat has issued updated RHEL 9 container images containing backported patches to fix this issue and recommends users upgrade and rebuild dependent container images. As a temporary mitigation, disabling the proxy server by setting INSIGHTS_ENABLED to false is possible, though it causes a crash loop in the Insights container, which is harmless. No active exploitation has been reported. The vulnerability is tracked under Red Hat advisory RHSA-2025:23236.

Potential Impact

An attacker with standard user privileges within the cluster can exploit this vulnerability to execute commands with the full permissions of the cluster administrator on the Red Hat management platform. This could lead to unauthorized changes to the cluster's configuration or status, potentially compromising cluster integrity and control. The vulnerability does not impact availability but has high confidentiality and integrity impacts.

Mitigation Recommendations

Red Hat has released updated RHEL 9 container images with backported patches that fix this vulnerability. Users of Red Hat Insights for Runtimes on RHEL 8 container images are advised to upgrade to these updated images and rebuild all dependent container images. As a temporary mitigation, the proxy server can be disabled by adding the environment variable INSIGHTS_ENABLED set to "false" in the Cryostat or JWS subscription YAML. This disables the affected proxy but causes a harmless crash loop in the Insights container. Users should apply all previously released errata relevant to their system before updating. Refer to Red Hat advisory RHSA-2025:23236 for detailed update instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2025-10-07T02:24:57.427Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/errata/RHSA-2025:23236","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2025-11393","vendor":"Red Hat"}]

Threat ID: 69404222d9bcdf3f3df0a13a

Added to database: 12/15/2025, 17:15:14 UTC

Last enriched: 08/13/2026, 16:42:54 UTC

Last updated: 09/10/2026, 19:36:49 UTC

Views: 391

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses