The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with developer persona to add callbacks to be executed to HTTP endpoints once the authorization process is completed. It was found that an attacker with developer persona access can add a large number of those callbacks to be executed by Authorino and as the authentication policy is enforced by a single instance of the service, this leada to a Denial of Service in Authorino while processing the post-authorization callbacks.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Jun 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 09 Jun 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with developer persona to add callbacks to be executed to HTTP endpoints once the authorization process is completed. It was found that an attacker with developer persona access can add a large number of those callbacks to be executed by Authorino and as the authentication policy is enforced by a single instance of the service, this leada to a Denial of Service in Authorino while processing the post-authorization callbacks. |
Title | RHCL: AuthPolicy Callbacks Result in Denial of Service in Authorino Severity | Rhcl: authpolicy callbacks result in denial of service in authorino severity |
First Time appeared |
Redhat
Redhat connectivity Link |
|
CPEs | cpe:/a:redhat:connectivity_link:1 | |
Vendors & Products |
Redhat
Redhat connectivity Link |
|
References |
|
Tue, 25 Feb 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | |
Title | RHCL: AuthPolicy Callbacks Result in Denial of Service in Authorino Severity | |
Weaknesses | CWE-400 CWE-703 |
|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published: 2025-06-09T06:12:51.416Z
Updated: 2025-06-09T18:11:15.868Z
Reserved: 2025-02-03T20:02:01.750Z
Link: CVE-2025-25207

Updated: 2025-06-09T18:09:37.757Z

Status : Awaiting Analysis
Published: 2025-06-09T06:15:24.413
Modified: 2025-06-09T12:15:47.880
Link: CVE-2025-25207
