CVE-2025-14243

A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-08 17:20

Updated : 2026-07-25 10:10


NVD link : CVE-2025-14243

Mitre link : CVE-2025-14243

CVE.ORG link : CVE-2025-14243


JSON object : View

Products Affected

redhat

  • mirror_registry_for_red_hat_openshift
CWE
CWE-209

Generation of Error Message Containing Sensitive Information