HomeRedhatCVE-2025-6920

CVE-2025-6920

MEDIUM
5.3CVSS
Published: 2025-07-01
Updated: 2025-08-18
AI Analysis

Description

A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enforce API key validation. However, the POST /invocations endpoint failed to do so, resulting in an authentication bypass. This vulnerability allows unauthorized users to access the same inference features available on protected endpoints, potentially exposing sensitive functionality or allowing unintended access to backend resources.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
low
Integrity
none
Availability
none
Weaknesses
CWE-306

Metadata

Primary Vendor
REDHAT
Published
7/1/2025
Last Modified
8/18/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

redhat : ai_inference_server

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-6920 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com