- Description
- A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
- Products
- mirror_registry_for_red_hat_openshift
CVSS 3.1
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
- secalert@redhat.com
- CWE-209
- Hype score
- Not currently trending
CVE-2025-14243 A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via … https://t.co/7iI6bodwNX
@CVEnew
8 Apr 2026
133 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-14243 Unauthenticated Username and Email Enumeration in OpenShift Mirro... https://t.co/Ma5mfInIJi Customizable Vulnerability Alerts: https://t.co/U7998fz7yk
@VulmonFeeds
8 Apr 2026
68 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*",
"matchCriteriaId": "63757310-FC5B-44E6-9211-36269827BC56",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "281E6AA4-1E08-488F-BA7A-F0BE7CF42A5B",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]