关键漏洞信息 漏洞标识符 CVE编号: CVE-2025-7195 影响等级 严重性: Moderate Impact CVSS v3 基本分数: 5.2 描述 漏洞类型: Privilege escalation due to insecure permissions of directories. 影响范围: Users with a UNIX/Linux UID, provided an empty home directory with incorrect permissions at the well-known location . 潜在风险: An attacker with container root could create a new group and add any arbitrary UID, escalating privileges down the chain. 缓解措施 默认配置: Red Hat OpenShift Container Platform includes default Security Context Constraints (SCCs) that prevent containers from running as root and writing to the host file system. 额外控制: Other environments may have different controls available for similar cross-container attacks. 受影响的包和发布的Red Hat安全公告 受影响的产品和服务: - Fuse Integration Operator - Nuxeo Engine for Kubernetes - Nuxeo Engine for Kubernetes - Nuxeo Engine for Kubernetes - Nuxeo Engine for Kubernetes - Nuxeo Engine for Kubernetes - Nuxeo Engine for Kubernetes - Nuxeo Engine for Kubernetes - Nuxeo Engine for Kubernetes - Nuxeo Engine for Kubernetes CVSS v3 分数详情 攻击向量: Local 攻击复杂度: High 所需权限: High 用户交互: None 作用范围: Changed 机密性影响: Low 完整性影响: High 可用性影响: Low 弱点理解 (CWE) CWE编号: CWE-276 描述: Confidentiality/Integrity TechnicalImpact:Read Application Data Modify Application Data