Incorrect default permissions in operator-sdk - CVE-2025-7195
Published: November 10, 2025 / Updated: January 19, 2026
Vulnerability identifier: #VU118221
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-7195
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due the user_setup script set insecure permissions for the /etc/passwd file. A local user with ability to execute commands within an affected container can escalate privileges on the system.
Affected software
operator-sdk
OpenShift Compliance Operator
Red Hat Advanced Cluster Management for Kubernetes
OpenShift File Integrity Operator
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Compliance Operator
Red Hat Advanced Cluster Management for Kubernetes
OpenShift File Integrity Operator
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2025-7195
Install updates from vendor's website.
operator-sdk - update to 0.15.2
OpenShift Compliance Operator - update to 1.8.1
Multicluster Engine for Kubernetes - addressed in versions 2.6, 2.8.4
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.11.9, 2.13.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.17.5
OpenShift File Integrity Operator - update to 1.3.8
OpenShift Compliance Operator - update to 1.8.1
Multicluster Engine for Kubernetes - addressed in versions 2.6, 2.8.4
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.11.9, 2.13.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.17.5
OpenShift File Integrity Operator - update to 1.3.8
External References
Related Security Bulletins
- Insecure default permissions in Operator-SDK
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.17
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.16
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.15
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.14
- Red Hat OpenShift File Integrity Operator update for operator-sdk
- Multiple vulnerabilities in Red Hat Multicluster Engine for Kubernetes
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.13
- Multiple vulnerabilities in Red Hat Multicluster Engine for Kubernetes 2.8
- OpenShift Compliance Operator update for operator-sdk