{"cve":{"cve_id":"CVE-2025-14243","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.00287,"epss_percentile":0.2076,"epss_as_of":"2026-08-26","description":"A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.","published_at":"2026-04-08T16:41:55.597000Z","last_modified_at":"2026-07-25T10:10:00.167000Z","cvss_v3_score":5.3,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cvss_v3_severity":"MEDIUM","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"none","ssvc_automatable":true,"ssvc_technical_impact":"partial","cwes":["CWE-209"],"nvd_references":["https://access.redhat.com/security/cve/CVE-2025-14243","https://bugzilla.redhat.com/show_bug.cgi?id=2419829"],"vuln_status":"Analyzed","trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-07-25T10:43:48.220773Z"},"effective_severity":"MEDIUM","badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"L","value_label":"Low"},{"metric":"I","name":"Integrity","value":"N","value_label":"None"},{"metric":"A","name":"Availability","value":"N","value_label":"None"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"redhat","vendor_name":"RedHat","product_slug":"mirror-registry-for-red-hat-openshift","product_name":"mirror_registry_for_red_hat_openshift","version_start":null,"version_start_inclusive":null,"version_end":null,"version_end_inclusive":null,"cpe23_uri":"cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*"},{"vendor_slug":"redhat","vendor_name":"RedHat","product_slug":"mirror-registry-for-red-hat-openshift","product_name":"mirror_registry_for_red_hat_openshift","version_start":"2.0","version_start_inclusive":true,"version_end":"2.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:*"}],"exploit_refs":[],"news":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2025-14243","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2419829","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2026-04-08T16:41:55.597000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:41:34.426622Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:41:34.426622Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:41:34.426622Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"ssvc_changed","at":"2026-06-29T23:46:59.033383Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T23:46:59.033383Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T23:46:59.033383Z","label":"SSVC decision revised","source":"vulnrichment"}]}