Insecure User Permissions in Operator-SDK from Red Hat
CVE-2025-7195
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 7 August 2025
What is CVE-2025-7195?
Early releases of the Operator-SDK from Red Hat contained a security flaw that allowed the /etc/passwd file to be built with insecure group-writable permissions. This issue arises from the use of the 'user_setup' script, which modifies file permissions during the container image build process. If an attacker gains access to an impacted container, they can exploit their non-root user membership in the root group to alter the /etc/passwd file. This exploitation could allow the attacker to create new user accounts with arbitrary user IDs, including root privileges, posing a severe security risk to the container and its environment.
Affected Version(s)
Compliance Operator 1 sha256:0903a7a5c857d96c84fd022e5785514eff201047e2fdd5d6699d79f17440ef02
multicluster engine for Kubernetes 2.7 sha256:d64f8dd4bc9c3c9cd4cde0d9c824a5554d3e3bad10cc45259f0cae1b49d60d72
multicluster engine for Kubernetes 2.7 sha256:4364624686c53f5996960296f8ce496ee819d500eab396f35f7bf417dfdf08b9