CVE Feed

    Dashboard / CVE / CVE-2025-5198

    CVE-2025-5198

    A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the name of a Kubernetes “Role” object* that is applied to a secured cluster. This object can be used by a user with access to the cluster or through a compromised third-party product.

    Published:May 26, 2025
    Last Modified:Feb 27, 2026
    EPS:May 27, 2025
    EPSS Score:0.00042
    CVSS Score:5

    Affected Products

    Vendor
    Redhat
    Product
    Advanced Cluster Security
    Vendor
    Stackrox
    Product
    Stackrox

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High