Threats Tagged 'cve-2025-64756'
View all threats tagged with 'cve-2025-64756'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-64756'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.19.4CVE-2025-6545 0 Red Hat OpenShift Pipelines Operator version 1. 19. 4 addresses multiple security issues identified in previous versions, including CVE-2025-6545 and related CVEs. The release fixes several bugs and vulnerabilities affecting pipeline execution, certificate handling, permission errors, and operator stability. These issues are categorized under CWE-20 (Improper Input Validation) and CWE-78 (OS Command Injection). The advisory does not provide a CVSS score but classifies the severity as high. No known exploits are reported in the wild. The patch status is indicated by the availability of the 1. 19. 4 release, which contains the fixes. Join the discussion | GCVE Database | 12/09/2025, 10:09:13 UTC Added: 05/26/2026, 20:58:28 UTC |
Red Hat Security Advisory: Kiali 1.73.25 for Red Hat OpenShift Service Mesh 2.6CVE-2025-12816 0 Red Hat OpenShift Service Mesh 2. 6 includes Kiali 1. 73. 25, which addresses multiple security vulnerabilities. These include an unbounded recursion issue in node-forge's ASN. 1 processing (CVE-2025-66031) and a command injection vulnerability in the glob CLI via the -c/--cmd option (CVE-2025-64756). These vulnerabilities could potentially be exploited to cause denial of service or arbitrary command execution. The advisory does not explicitly state that a patch is available but references Kiali 1. 73. 25 as the fixed version. Join the discussion | GCVE Database | 12/09/2025, 14:58:58 UTC Added: 05/26/2026, 20:58:28 UTC |
Red Hat Security Advisory: Kiali 2.11.5 for Red Hat OpenShift Service Mesh 3.1CVE-2025-12816 0 Red Hat OpenShift Service Mesh 3. 1's Kiali component version 2. 11. 5 addresses multiple security vulnerabilities including an unbounded recursion issue in node-forge ASN. 1 processing (CVE-2025-66031) and a command injection vulnerability in the glob CLI via the -c/--cmd option (CVE-2025-64756). These vulnerabilities could potentially allow attackers to cause denial of service or execute arbitrary commands. The update to Kiali 2. 11. 5 includes fixes for these issues. The vendor advisory classifies the security impact as Moderate and does not indicate known exploits in the wild. Join the discussion | GCVE Database | 12/09/2025, 14:59:35 UTC Added: 05/26/2026, 20:58:28 UTC |
Red Hat Security Advisory: Kiali 2.17.2 for Red Hat OpenShift Service Mesh 3.2CVE-2025-12816 0 Red Hat OpenShift Service Mesh 3. 2 includes Kiali 2. 17. 2, which addresses multiple security vulnerabilities. These include an unbounded recursion issue in the node-forge ASN. 1 parser (CVE-2025-66031) and a command injection vulnerability in the glob CLI when using the -c/--cmd option with shell:true (CVE-2025-64756). These vulnerabilities are rated as high severity and could impact the security of the service mesh observability component. The advisory does not explicitly state that a patch is available but references Kiali 2. 17. 2 as the fixed version. Join the discussion | GCVE Database | 12/09/2025, 15:24:58 UTC Added: 05/26/2026, 20:58:28 UTC |
Red Hat Security Advisory: Kiali 2.4.11 for Red Hat OpenShift Service Mesh 3.0CVE-2025-12816 0 Red Hat has issued a security advisory for Kiali 2. 4. 11 used in Red Hat OpenShift Service Mesh 3. 0 addressing multiple vulnerabilities. These include an unbounded recursion issue in the node-forge ASN. 1 parser (CVE-2025-66031) and a command injection vulnerability in the glob CLI via the -c/--cmd option (CVE-2025-64756). The vulnerabilities affect the kiali-ossmc-rhel9 and kiali-rhel9 components. The advisory classifies the severity as high but does not provide a CVSS score or explicit patch details. No known exploits in the wild have been reported. The advisory references updated documentation for Kiali 2. Join the discussion | GCVE Database | 12/09/2025, 14:59:02 UTC Added: 05/26/2026, 20:58:28 UTC |
Red Hat Security Advisory: RHTAS 1.2.2 - Red Hat Trusted Artifact Signer ReleaseCVE-2025-64756 0 This advisory concerns the Red Hat Trusted Artifact Signer (RHTAS) Operator versions compatible with OpenShift Container Platform 4. 15 through 4. 19. It references multiple CVEs including CVE-2025-64756 and others, indicating several vulnerabilities related to this product. The advisory does not provide details on specific fixes or patches for these vulnerabilities. RHTAS is a self-managed on-premise deployment of the Sigstore project used to cryptographically sign and verify software artifacts to ensure supply chain integrity. No known exploits in the wild have been reported. The vendor advisory does not explicitly state that a patch or fix is available for these vulnerabilities. Join the discussion | GCVE Database | 02/18/2026, 12:44:08 UTC Added: 05/26/2026, 20:58:26 UTC |
Red Hat Security Advisory: RHTAS 1.3.2 - Red Hat Trusted Artifact Signer ReleaseCVE-2025-61729 0 The Red Hat Trusted Artifact Signer (RHTAS) Operator version 1. 3. 2 is associated with multiple security vulnerabilities identified by CVE-2025-61729 and 11 additional CVEs. It is designed for use with OpenShift Container Platform versions 4. 16 through 4. 20 and facilitates cryptographic signing and verification of software artifacts. The advisory does not specify any fixes or patches for these vulnerabilities. The product is a self-managed on-premise deployment of the Sigstore project, aimed at ensuring software supply chain integrity. No known exploits are reported in the wild at this time. Join the discussion | GCVE Database | 02/05/2026, 15:45:43 UTC Added: 05/26/2026, 20:58:25 UTC |
Red Hat Security Advisory: Red Hat Developer Hub 1.7.4 release.CVE-2025-12816 0 Red Hat Developer Hub (RHDH) version 1. 7. 4 addresses multiple security vulnerabilities identified under CVE-2025-12816 and related CVEs. RHDH is an enterprise-grade, self-managed developer portal based on Backstage. io, supporting Kubernetes clusters such as OpenShift, AKS, EKS, and GKE. The advisory indicates the release of RHDH 1. 7. 4 as a security update but does not specify individual vulnerability details or exploitation methods. No known exploits are reported in the wild. Patch status is not explicitly confirmed in the advisory, and no direct fixes are listed, suggesting users should consult the vendor advisory for current remediation guidance. Join the discussion | GCVE Database | 01/07/2026, 18:34:52 UTC Added: 05/26/2026, 20:58:24 UTC |
Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usageCVE-2024-5642 0 CVE-2024-5642 concerns Red Hat Discovery, a tool that inspects and reports environment data such as system counts, operating systems, and configuration details within a network. The advisory identifies this as a high-severity vulnerability affecting multiple Red Hat Discovery versions and related products. The vendor advisory does not indicate any available patches or fixes at this time. No known exploits are reported in the wild. The vulnerability is part of a broader advisory covering multiple CVEs related to Red Hat Discovery and subscription management tools. Join the discussion | GCVE Database | 01/08/2026, 22:34:17 UTC Added: 05/26/2026, 20:58:24 UTC |
Red Hat Security Advisory: Red Hat Developer Hub 1.8.2 release.CVE-2025-15284 0 Red Hat Developer Hub (RHDH) version 1. 8. 2 addresses multiple security vulnerabilities identified by CVE-2025-15284, CVE-2025-64756, and CVE-2025-65945. RHDH is an enterprise-grade, self-managed developer portal based on Backstage. io, supporting Kubernetes clusters such as OpenShift, AKS, EKS, and GKE. The advisory notes these vulnerabilities but does not provide details on fixes or patches in the published advisory. No known exploits are reported in the wild. The vulnerabilities relate to issues categorized under CWE-770 (Allocation of Resources Without Limits or Throttling), CWE-78 (OS Command Injection), and CWE-347 (Improper Verification of Cryptographic Signature). Join the discussion | GCVE Database | 01/13/2026, 21:28:08 UTC Added: 05/26/2026, 20:58:24 UTC |
Showing 1 to 10 of 15 results