CVE-2025-5417 - CVE House
Back to Database
Status published Medium CVE-2025-5417

Rhdh: red hat developer hub user permissions

Vulnerability Description

An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cluster admin/user, who has standard user access to the cluster, and the Red Hat Developer Hub namespace, can access the rhdh/rhdh-hub-rhel9 container image and modify the image's content. This issue affects the confidentiality and integrity of the data, and any changes made are not permanent, as they reset after the pod restarts.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5417

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat Developer Hub, Red Hat Developer Hub 1.7
Vulnerable Versions:
0, sha256:aa3c5b50c65aee51b932fafcbf479ce54f15496cffc2744860bd9e135cce815c

Timeline

Official Publish: August 19th, 2025
Last Modified: December 19th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)