Junglewise Threat Intelligence

CVE-2025-11393: Red Hat Runtimes Inventory Operator improper proxy configuration

CVE-2025-11393 · Severity: high · CVSS 8.7 · Published 2025-12-15

Vendors: Red Hat, Go.

Executive brief

A security flaw exists in a Red Hat component used to manage and inventory software runtimes within a cluster. An incorrectly configured internal proxy allows a standard user to trick the system into using high-level administrative credentials for unauthorized commands. This could allow a non-privileged user to gain full control over the cluster's configuration and status on the Red Hat platform, potentially leading to unauthorized changes or service disruption.

Technical details

A 'Confused Deputy' vulnerability (CWE-441) exists in the runtimes-inventory-rhel8-operator due to an improperly configured internal proxy component. The proxy incorrectly attaches the cluster's primary administrative credentials to any incoming command it receives, rather than restricting credential attachment to authorized reporting tasks. An attacker with standard user access within the cluster (adjacent network) can leverage this to send unauthorized requests to the management platform with full administrative permissions. This allows for unauthorized modification of cluster configuration or status. Red Hat has released updated container images (RHSA-2025:23236) to address this issue.

Affected products

  • Red Hat Red Hat Lightspeed (formerly Insights) for Runtimes 1.0 versions prior to 1.0.0-1765483112
  • Red Hat Red Hat Runtimes Inventory Operator all versions on RHEL 8

Timeline

  • 2025-10-07: other: Vulnerability reported to Red Hat Bugzilla
  • 2025-12-15: disclosed: Public disclosure of CVE-2025-11393
  • 2025-12-16: patched: Red Hat Security Advisory RHSA-2025:23236 issued

References