CVE-2025-6020
HighAdvisory
Published 17 Jun 2025In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.8
- base score, highest
- EPSS
- 0.004
- 37th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,388
- of 17,787 indexed, latest versions
- Container images
- 1,464
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Red Hat Security Advisory: pam security update
Carried by container images the latest versions of 1,388 of 17,787 indexed charts deploy, on 1,464 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pamdeb | 1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+24 more | 1.4.0-11ubuntu2.6, 1.5.2-6+deb12u2, 1.5.3-5ubuntu5.4 | 1,338 |
| pamrpm | 1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-lp151.7.38, 1.3.1-4.el8+18 more | 0:1.1.8-23.el7_9.1, 0:1.3.1-37.el8_10, 0:1.5.1-15.el9_2.1, 0:1.5.1-24.el9_4+2 more | 126 |
- OSV records
- DEBIAN-CVE-2025-6020RHSA-2025:10024RHSA-2025:10027RHSA-2025:10180RHSA-2025:10357RHSA-2025:9526RLSA-2025:10027RLSA-2025:9526UBUNTU-CVE-2025-6020openSUSE-SU-2025:15256-1
- Also known as
- RHSA-2025:10358, RHSA-2025:10359, RHSA-2025:10361, RHSA-2025:10362, USN-7580-1
Charts affected
1,388 by stars
Container images carrying it
1,464 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| coderenvs/ | 76fd37fe6830 | pam | 0:1.3.1-37.el8_10 | 1 |
| codetogether/ | 4348c8a38752 | pam | 0:1.5.1-24.el9_4 | 1 |
| collabora/ | 01dc4ab83977 | pam | 1.5.2-6+deb12u2 | 1 |
| collabora/ | 05299b452f7f | pam | 1.5.2-6+deb12u2 | 1 |
| confluentinc/ | f2975d507a2a | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | 8f1544df1f48 | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | 3bf359d5e340 | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | 83dbca3efd2a | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | adc392d28a1e | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | c0224a1adf7a | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | dc9b972db002 | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | 4bc70a83ca6f | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | b0b7aa26254a | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | 8ec46c27982f | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | ee403d5b9090 | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | b651d4b6185a | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | 0bec03c1f3ce | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | 5ca5f3269814 | pam | 0:1.3.1-37.el8_10 | 1 |
| confluentinc/ | 78c190f4472c | pam | 0:1.3.1-37.el8_10 | 1 |
| consensys/ | bf6ecd2ea716 | pam | 1.5.3-5ubuntu5.4 | 1 |
| contentsquareplatform/ | 24555f22d4be | pam | 1.5.2-6+deb12u2 | 1 |
| cortezaproject/ | 8eb7a26605c9 | pam | no fix listed | 1 |
| cortezaproject/ | 4ea78dfe5364 | pam | 1.5.2-6+deb12u2 | 1 |
| countly/ | e3c238248f99 | pam | no fix listed | 1 |
| cradlepoint/ | 8f5720b0cd03 | pam | no fix listed | 1 |
| cribl/ | 762747cb6796 | pam | no fix listed | 1 |
| csiplugin/ | 1fa83d45417f | pam | no fix listed | 1 |
| cubejs/ | 34ac523a9bab | pam | 1.5.2-6+deb12u2 | 1 |
| dachichang/ | 7ccac90a935e | pam | 1.5.2-6+deb12u2 | 1 |
| daedalusproject/ | 6f72b5119eda | pam | no fix listed | 1 |
| danialnabiyan1382/ | f96a7ebf1f42 | pam | 1.5.2-6+deb12u2 | 1 |
| dannielkil/ | 937993927694 | pam | 1.5.2-6+deb12u2 | 1 |
| darthsim/ | 476cb08c816a | pam | 1.5.3-5ubuntu5.4 | 1 |
| daskdev/ | 052630f5ca04 | pam | no fix listed | 1 |
| dasmeta/ | fa657960dfec | pam | no fix listed | 1 |
| datadog/ | aad9994de6a7 | pam | 1.5.3-5ubuntu5.4 | 1 |
| datafuselabs/ | ba877ee6cb4d | pam | 1.5.2-6+deb12u2 | 1 |
| datafuselabs/ | a936843b85b4 | pam | 1.5.2-6+deb12u2 | 1 |
| datalayers/ | 17b292079239 | pam | 1.4.0-11ubuntu2.6 | 1 |
| datalust/ | 9c731bb207a6 | pam | no fix listed | 1 |
| datalust/ | 3de34aed5642 | pam | no fix listed | 1 |
| dblaci/ | eea697611af4 | pam | 1.4.0-11ubuntu2.6 | 1 |
| ddosify/ | ea602056d9ce | pam | 1.5.2-6+deb12u2 | 1 |
| ddosify/ | a43c5155fa1c | pam | 1.5.2-6+deb12u2 | 1 |
| ddosify/ | 3c11e3182652 | pam | 1.5.2-6+deb12u2 | 1 |
| ddosify/ | ac323d52bfb4 | pam | 1.5.2-6+deb12u2 | 1 |
| ddosify/ | b796b8c73011 | pam | 1.5.2-6+deb12u2 | 1 |
| deconzcommunity/ | 062de2362641 | pam | 1.5.2-6+deb12u2 | 1 |
| deepflowce/ | bc1882f75c18 | pam | no fix listed | 1 |
| deepflowce/ | 29332fee7fc2 | pam | 1.4.0-11ubuntu2.6 | 1 |