THREAT OPS › Threat News › [NVD] CVE-2025-7195 (MEDIUM 6.4) — Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Develo
[NVD] CVE-2025-7195 (MEDIUM 6.4) — Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Develo
CVE-2025-7195 CVSS: 6.4 MEDIUM Published: 2025-08-07T19:15:29.367
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold
Indicators of compromise
- CVE-2025-7195cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-7195