Story perspectives
Critical Flaw in Red Hat's OpenShift AI Exposes Clusters
10/2/2025
38 4
1 of 1
Story summary
- Red Hat's OpenShift AI service exposes CVE-2025-10725, a critical flaw (CVSS 9.9) that lets low-privileged, authenticated users gain full cluster control.
- Misconfigured ClusterRoleBindings link the kueue-batch-user-role to system:authenticated, enabling unauthorized job creation.
- Red Hat classifies the flaw as "Important" due to minimal authentication needed to exploit.
- Experts urge patching and role audits; security teams should enforce least-privilege policies and conduct regular reviews.
