Get real-time updates on Telegram
CVE-2025-11060: OpenShift Service Mesh 3 (exact versions not specified)
CVE-2025-11060. CVSS 3.1 base score 5.7 (MEDIUM, Vendor/CNA). EPSS 0.0032 (percentile 0.22923), scored 2026-10-08.
Affected technology
Product not specified by the source · 0 to before 2.1.9, 2.2.0 to before 2.2.8, 2.3.0 to before 2.3.8, 3.3.0 to before 3.3.0-alpha.7
Vendor not specified by the source
OpenShift Service Mesh 3 · Exact affected versions not specified by the source
Red Hat
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · Low privileges required · User interaction required
What an attacker can do
Record or guest users can observe unauthorized records within the same table, bypassing access controls, via crafted LIVE SELECT subscriptions when other users alter or delete records. Vendor/CNA’s CVSS 3.1 assessment (base score 5.7/10) rates confidentiality impact as high; integrity and availability impact as none.
- CWE
- CWE-863
- CCR priority
- 22.9 /100 (P4)
- CVSS 3.1
- 5.7 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N · Vendor/CNA
- EPSS
- 0.0032 · percentile 0.22923 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 12:21:30.679837+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-11060.html