Red Hat Security Advisory: Red Hat OpenShift Builds 1.4.1
Releases of Red Hat OpenShift Builds 1.4.1
AI Analysis
Technical Summary
CVE-2025-47273 is a path traversal vulnerability in the setuptools PackageIndex component of python-setuptools. This vulnerability allows an attacker to potentially manipulate file paths in a way that could lead to unauthorized file access or modification. Red Hat has issued security advisories (RHSA-2025:11427 and RHSA-2025:10787) addressing this issue for Red Hat Enterprise Linux versions 8.8 and 10.0, including related products such as Red Hat OpenShift Builds. The vulnerability is rated as moderate in severity by Red Hat. No CVSS base score is currently available. The advisories provide updated package versions that fix the issue.
Potential Impact
The vulnerability could allow unauthorized path traversal attacks via the setuptools PackageIndex, potentially leading to unauthorized file access or modification. Red Hat rates the impact as moderate. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released updated python-setuptools packages that address this vulnerability. Users of affected Red Hat Enterprise Linux 8.8 and 10.0 versions, as well as Red Hat OpenShift Builds 1.3.z, should apply the provided updates (e.g., python-setuptools-39.2.0-7.el8_8.3) as detailed in Red Hat advisories RHSA-2025:11427 and RHSA-2025:10787. Refer to Red Hat's official update instructions at https://access.redhat.com/articles/11258. No additional mitigation steps are indicated by the vendor.
Red Hat Security Advisory: Red Hat OpenShift Builds 1.4.1
Description
Releases of Red Hat OpenShift Builds 1.4.1
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-47273 is a path traversal vulnerability in the setuptools PackageIndex component of python-setuptools. This vulnerability allows an attacker to potentially manipulate file paths in a way that could lead to unauthorized file access or modification. Red Hat has issued security advisories (RHSA-2025:11427 and RHSA-2025:10787) addressing this issue for Red Hat Enterprise Linux versions 8.8 and 10.0, including related products such as Red Hat OpenShift Builds. The vulnerability is rated as moderate in severity by Red Hat. No CVSS base score is currently available. The advisories provide updated package versions that fix the issue.
Potential Impact
The vulnerability could allow unauthorized path traversal attacks via the setuptools PackageIndex, potentially leading to unauthorized file access or modification. Red Hat rates the impact as moderate. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released updated python-setuptools packages that address this vulnerability. Users of affected Red Hat Enterprise Linux 8.8 and 10.0 versions, as well as Red Hat OpenShift Builds 1.3.z, should apply the provided updates (e.g., python-setuptools-39.2.0-7.el8_8.3) as detailed in Red Hat advisories RHSA-2025:11427 and RHSA-2025:10787. Refer to Red Hat's official update instructions at https://access.redhat.com/articles/11258. No additional mitigation steps are indicated by the vendor.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:15408
- Cve Count
- 1
Threat ID: 6a1f4e87e29bf47b50081895
Added to database: 06/02/2026, 21:43:35 UTC
Last enriched: 08/17/2026, 17:02:22 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.