CVE Vulnerabilities

CVE-2025-7783

Use of Insufficiently Random Values

Published: Jul 18, 2025 | Modified: Jul 22, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.4 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Ubuntu
MEDIUM

Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js.

This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.

Weakness

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Affected Software

Name Vendor Start Version End Version
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-agent-init-rhel9:0.5.2-3 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-db-rhel9:4.0.2-3 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-grafana-dashboard-rhel9:4.0.2-3 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-openshift-console-plugin-rhel9:4.0.2-3 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-operator-bundle:4.0.2-3 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-ose-oauth-proxy-rhel9:4.0.2-3 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-reports-rhel9:4.0.2-3 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-rhel9:4.0.2-3 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-rhel9-operator:4.0.2-3 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-storage-rhel9:4.0.2-3 *
Cryostat 4 on RHEL 9 RedHat cryostat/jfr-datasource-rhel9:4.0.2-3 *
Multicluster engine for Kubernetes 2.8 for RHEL 8 RedHat multicluster-engine-assisted-service-8-container-v2.8.3-14 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-addon-manager-container-v2.8.3-14 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-assisted-image-service-container-v2.8.3-15 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-assisted-installer-agent-container-v2.8.3-16 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-assisted-installer-container-v2.8.3-18 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-assisted-installer-controller-container-v2.8.3-18 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-assisted-service-9-container-v2.8.3-16 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-cluster-api-provider-agent-container-v2.8.3-7 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-cluster-api-provider-kubevirt-container-v2.8.3-7 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-clusterclaims-controller-container-v2.8.3-11 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-cluster-curator-controller-container-v2.8.3-11 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-cluster-image-set-controller-container-v2.8.3-10 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-clusterlifecycle-state-metrics-container-v2.8.3-8 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-cluster-proxy-addon-container-v2.8.3-10 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-cluster-proxy-container-v2.8.3-10 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-console-mce-container-v2.8.3-13 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-discovery-operator-container-v2.8.3-10 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-hive-container-v2.8.3-8 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-hypershift-addon-operator-container-v2.8.3-9 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-hypershift-cli-container-v2.8.3-13 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-hypershift-operator-container-v2.8.3-11 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-image-based-install-container-v2.8.3-31 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-kube-rbac-proxy-mce-container-v2.8.3-7 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-managedcluster-import-controller-container-v2.8.3-10 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-managed-serviceaccount-container-v2.8.3-9 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-multicloud-manager-container-v2.8.3-11 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-must-gather-container-v2.8.3-14 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-operator-bundle-container-v2.8.3-24 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-operator-container-v2.8.3-10 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-placement-container-v2.8.3-14 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-provider-credential-controller-container-v2.8.3-11 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-registration-container-v2.8.3-14 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-registration-operator-container-v2.8.3-14 *
Multicluster engine for Kubernetes 2.8 for RHEL 9 RedHat multicluster-engine-work-container-v2.8.3-14 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-cli-container-v2.13.4-14 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-cluster-permission-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-governance-policy-addon-controller-container-v2.13.4-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-governance-policy-framework-addon-container-v2.13.4-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-grafana-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-multicluster-observability-addon-container-v2.13.4-14 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-must-gather-container-v2.13.4-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-operator-bundle-container-v2.13.4-22 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-prometheus-config-reloader-container-v2.13.4-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-prometheus-operator-container-v2.13.4-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-search-indexer-container-v2.13.4-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-search-v2-api-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-search-v2-operator-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-siteconfig-container-v2.13.4-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-volsync-addon-controller-container-v2.13.4-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat cert-policy-controller-container-v2.13.4-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat cluster-backup-operator-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat config-policy-controller-container-v2.13.4-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat console-container-v2.13.4-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat endpoint-monitoring-operator-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat governance-policy-propagator-container-v2.13.4-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat grafana-dashboard-loader-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat insights-client-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat insights-metrics-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat klusterlet-addon-controller-container-v2.13.4-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat kube-rbac-proxy-container-v2.13.4-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat kube-state-metrics-container-v2.13.4-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat memcached-exporter-container-v2.13.4-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat metrics-collector-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat multicloud-integrations-container-v2.13.4-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat multiclusterhub-operator-container-v2.13.4-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat multicluster-observability-operator-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat multicluster-operators-application-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat multicluster-operators-channel-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat multicluster-operators-subscription-operator-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat node-exporter-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat observatorium-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat observatorium-operator-container-v2.13.4-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat prometheus-alertmanager-container-v2.13.4-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat prometheus-container-v2.13.4-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rbac-query-proxy-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rhacm2/acm-flightctl-api-rhel9:v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rhacm2/acm-flightctl-ocp-ui-rhel9:v2.13.4-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rhacm2/acm-flightctl-periodic-rhel9:v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rhacm2/acm-flightctl-ui-rhel9:v2.13.4-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rhacm2/acm-flightctl-worker-rhel9:v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rhacm2/memcached-rhel9:v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat search-collector-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat submariner-addon-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat thanos-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat thanos-receive-controller-container-v2.13.4-11 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-main-rhel8:sha256:5a6329620e5853afef9ca9ac46e254859d3f254a5976f67272c1c0f85de20af5 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-main-rhel8:sha256:5a6329620e5853afef9ca9ac46e254859d3f254a5976f67272c1c0f85de20af5 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-main-rhel8:sha256:5a6329620e5853afef9ca9ac46e254859d3f254a5976f67272c1c0f85de20af5 *
Red Hat Advanced Cluster Security 4.8 RedHat advanced-cluster-security/rhacs-main-rhel8:sha256:29498f45f5529c17af3ad900983ee28d37e2954828d56acc20894bf06e9c4e9d *

Potential Mitigations

  • Use a well-vetted algorithm that is currently considered to be strong by experts in the field, and select well-tested implementations with adequate length seeds.
  • In general, if a pseudo-random number generator is not advertised as being cryptographically secure, then it is probably a statistical PRNG and should not be used in security-sensitive contexts.
  • Pseudo-random number generators can produce predictable numbers if the generator is known and the seed can be guessed. A 256-bit seed is a good starting point for producing a “random enough” number.

References