Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-1767

Опубликовано: 13 мар. 2025
Источник: debian

Описание

This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kubernetesfixed1.20.5+really1.20.2-1package

Примечания

  • Server components no longer built since 1.20.5+really1.20.2-1, marking that as fixed version

  • The source package itself it still vulnerable, but custom rebuilds are not really a usecase here

  • https://groups.google.com/g/kubernetes-security-announce/c/19irihsKg7s

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.

CVSS3: 6.5
redhat
3 месяца назад

This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.

CVSS3: 6.5
nvd
3 месяца назад

This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.

CVSS3: 6.5
github
3 месяца назад

Kubernetes GitRepo Volume Inadvertent Local Repository Access

CVSS3: 6.5
fstec
3 месяца назад

Уязвимость функции gitRepo программного средства управления кластерами виртуальных машин Kubernetes, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации