A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2025-14243 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2419829 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Apr 2026, 18:06
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:* |
|
| First Time |
Redhat
Redhat mirror Registry For Red Hat Openshift |
|
| References | () https://access.redhat.com/security/cve/CVE-2025-14243 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2419829 - Issue Tracking, Vendor Advisory |
08 Apr 2026, 17:20
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-08 17:20
Updated : 2026-04-21 18:06
NVD link : CVE-2025-14243
Mitre link : CVE-2025-14243
CVE.ORG link : CVE-2025-14243
JSON object : View
Products Affected
redhat
- mirror_registry_for_red_hat_openshift
CWE
CWE-209
Generation of Error Message Containing Sensitive Information
