CVE-2025-14243

A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:*

History

21 Apr 2026, 18:06

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:*
First Time Redhat
Redhat mirror Registry For Red Hat Openshift
References () https://access.redhat.com/security/cve/CVE-2025-14243 - () https://access.redhat.com/security/cve/CVE-2025-14243 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2419829 - () https://bugzilla.redhat.com/show_bug.cgi?id=2419829 - Issue Tracking, Vendor Advisory

08 Apr 2026, 17:20

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 17:20

Updated : 2026-04-21 18:06


NVD link : CVE-2025-14243

Mitre link : CVE-2025-14243

CVE.ORG link : CVE-2025-14243


JSON object : View

Products Affected

redhat

  • mirror_registry_for_red_hat_openshift
CWE
CWE-209

Generation of Error Message Containing Sensitive Information