CVE-2025-5198
A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the name of a Kubernetes “Role” object* that is applied to a secured cluster. This object can be used by a user with access to the cluster or through a compromised third-party product.
Published:May 26, 2025
Last Modified:Feb 27, 2026
EPS:May 27, 2025
EPSS Score:0.00042
CVSS Score:5
Affected Products
Vendor
Product
Action
Vendor
Redhat
Product
Advanced Cluster Security
Redhat
Advanced Cluster Security
Vendor
Stackrox
Product
Stackrox
Stackrox
Stackrox
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
