RHSA-2025:23236HighCVSS 8.7
Red Hat Security Advisory: Red Hat Lightspeed (formerly Insights) for Runtimes 1.0.0: new RHEL 9 container image security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-11393 — insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: Improper Proxy Configuration Allows Unauthorized Administrative Commands CVE-2025-22874 — crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2025:23236
- externalhttps://access.redhat.com/security/cve/CVE-2025-11393
- externalhttps://access.redhat.com/security/cve/CVE-2025-22874
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23236.json