CVE-2024-25132

Aliases:GHSA-c392-wrgw-jjfwGO-2025-3536
Advisory lineage Upstream: 0 Downstream: 1
Deferred
Published: 19 Mar 2025, 17:57
Last modified:23 Jul 2025, 17:37

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.17% LOW
0% probability +0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Mar 2025, 17:57
Published
Vulnerability first disclosed
23 Jul 2025, 17:37
Last Modified
Vulnerability information updated

Description

A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to true, regardless of the installation status, and a positive timespan for the spec.hibernateAfter value. If a ClusterSync.hiveinternal.openshift.io/v1alpha1 resource is also created, the hive hibernation controller will enter the reconciliation loop leading to a panic when accessing a non-existing field in the ClusterDeployment’s status section, resulting in a denial of service.

CVSS Metrics

  • v3.1MEDIUMScore: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

EPSS Trends

Current EPSS score: 0.17% Percentile: 38%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • github.com/openshifthive

    ≤ 1.1.16 | all

References (5)