Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-5187

Опубликовано: 27 авг. 2025
Источник: debian
EPSS Низкий

Описание

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kubernetesfixed1.20.5+really1.20.2-1package

Примечания

  • Server components no longer built since 1.20.5+really1.20.2-1, marking that as fixed version

  • The source package itself it still vulnerable, but custom rebuilds are not really a usecase here

  • https://github.com/kubernetes/kubernetes/issues/133471

  • https://groups.google.com/g/kubernetes-security-announce/c/znSNY7XCztE

EPSS

Процентиль: 4%
0.0002
Низкий

Связанные уязвимости

CVSS3: 6.7
ubuntu
13 дней назад

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

CVSS3: 6.7
redhat
28 дней назад

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

CVSS3: 6.7
nvd
13 дней назад

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

CVSS3: 6.7
github
13 дней назад

Kubernetes Nodes can delete themselves by adding an OwnerReference

EPSS

Процентиль: 4%
0.0002
Низкий