Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:8265 - Security Advisory
Issued:
2025-06-05
Updated:
2025-06-05

RHSA-2025:8265 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Red Hat build of Cryostat 4.0.1: new RHEL 9 container image security update

Type/Severity

Security Advisory: Important

Topic

New Red Hat build of Cryostat 4.0.1 on RHEL 9 container images are now available.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The Cryostat 4 on RHEL 9 container images have been updated to fix several bugs.

Users of Cryostat 4 on RHEL 9 container images are advised to upgrade to these updated images, which contain backported patches to fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

Security Fix(es):

  • commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default (CVE-2025-48734)

You can find images updated by this advisory in the Red Hat Container Catalog (see the References section).

Solution

You can download the Cryostat 4 on RHEL 9 container images that this update provides from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available in the Red Hat Container Catalog (see the References section).

Dockerfiles and scripts should be amended to refer to this new image specifically or to the latest image generally.

Affected Products

  • Cryostat 4 x86_64

Fixes

  • BZ - 2368956 - CVE-2025-48734 commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
  • JAVAMON-748 - DNS resolution of callback only happens once at startup

CVEs

  • CVE-2025-48734

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/containers

aarch64

cryostat/cryostat-agent-init-rhel9@sha256:afeb514d720efeb572ea37cce6a53b0b0b5653204319742aba0692a536a80361
cryostat/cryostat-db-rhel9@sha256:e778ec192ae0ad6e2e17d0408283103c80823f5d972fdeec28ed11481774e343
cryostat/cryostat-grafana-dashboard-rhel9@sha256:1ec6c04eaf47d77a66019056693267216629c7851548390f256506620855a70f
cryostat/cryostat-openshift-console-plugin-rhel9@sha256:d20f8a89516e4e2a46587a1cfde252b6a8b6847e1be9b702bdff40b937db8c9d
cryostat/cryostat-operator-bundle@sha256:81f9daa32e9dbdf2134984fed8d8a7869bac0331e04c63766a8ebaf11c1bd278
cryostat/cryostat-ose-oauth-proxy-rhel9@sha256:1c4ec22a27a59bf85efbfe87cf4795124963155cad2a7c81353302899a4433a4
cryostat/cryostat-reports-rhel9@sha256:8024c6ed541228cad255f5aad072ceb76c094658b83e1affda8f80eaa304a5ae
cryostat/cryostat-rhel9@sha256:9912f12b6844c3b55d2eab6c97d4d28c5fe4451a24467fa029156a90f5baab6d
cryostat/cryostat-rhel9-operator@sha256:49680a8ad15aeaf8bab207e889b51d97fd913b738cc6cadc7e124aee70905c83
cryostat/cryostat-storage-rhel9@sha256:158486d58737ee242f4b29067521b999ce9f30a05640e8f70aadf0faa04e20e3
cryostat/jfr-datasource-rhel9@sha256:2718502db6176d8041c8848232c7e446ecfc75314757088ce3a6856e595ab0f6

x86_64

cryostat/cryostat-agent-init-rhel9@sha256:eef9de43eed816fd525d7f5c6c4833878a35fd4fc4bb4d1bea63a6f6411a7dfb
cryostat/cryostat-db-rhel9@sha256:e9dfc590abb8bf670d389663e9d176d61e120f0002adaf825661b8d794728ed8
cryostat/cryostat-grafana-dashboard-rhel9@sha256:eb54379f4712ce4411714392cd6a938109d66b0426214ed71d4ed7abbcdc7b6c
cryostat/cryostat-openshift-console-plugin-rhel9@sha256:ef494651e62b2310ff1fe768d1c6a4064d9e6409f676c180bd79c5a95d2698a3
cryostat/cryostat-operator-bundle@sha256:65420aedc7224553a355f9fb6ce917c574bcf927ffb4df4f1f4ea78988f2975c
cryostat/cryostat-ose-oauth-proxy-rhel9@sha256:6f8e65997ae1b865b8335081c8e37f338f2e915a213d061c7233508569108184
cryostat/cryostat-reports-rhel9@sha256:ef24bafda631eaca77f8f590b407942ddcb41dd1f8810a2004ccfe979cd90986
cryostat/cryostat-rhel9@sha256:2a51e2df3a109276fef06ad5ab4b8e7c434f6a8ef873e7cad0ca2c4f21f2c8a1
cryostat/cryostat-rhel9-operator@sha256:c14e0844de0890544c936417d9f2211f168f86115cd0e2b069b5c3e3f0556a88
cryostat/cryostat-storage-rhel9@sha256:1091a400851e64280da67a4b582db29f5790fca63136b0cc3c5c5e0db07cce00
cryostat/jfr-datasource-rhel9@sha256:25e0b03fa10a3cfa42b597a6e8823f12d0e4208f5fe51f3394809453f0fa4072

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility