Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3hw7-qj9h-r835

Опубликовано: 19 мая 2025
Источник: github
Github: Прошло ревью
CVSS3: 9.9

Описание

Gardener allows bypassing project secret validation which can lead to privilege escalation

A security vulnerability was discovered in Gardener that could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed.

Am I Vulnerable?

This CVE affects all Gardener installations no matter of the public cloud provider(s) used for the seed clusters/shoot clusters.

Affected Components

  • gardener/gardener

Affected Versions

  • < v1.116.4
  • < v1.117.5
  • < v1.118.2
  • < v1.119.0

Fixed Versions

  • >= v1.116.4
  • >= v1.117.5
  • >= v1.118.2
  • >= v1.119.0

How do I mitigate this vulnerability?

Update to a fixed version.

Пакеты

Наименование

github.com/gardener/gardener

go
Затронутые версииВерсия исправления

< 1.116.4

1.116.4

Наименование

github.com/gardener/gardener

go
Затронутые версииВерсия исправления

>= 1.117.0, < 1.117.5

1.117.5

Наименование

github.com/gardener/gardener

go
Затронутые версииВерсия исправления

>= 1.118.0, < 1.118.2

1.118.2

EPSS

Процентиль: 36%
0.00151
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-20
CWE-269

Связанные уязвимости

CVSS3: 9.9
nvd
9 месяцев назад

Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0 that could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed. This CVE affects all Gardener installations no matter of the public cloud provider(s) used for the seed clusters/shoot clusters. `gardener/gardener` (`gardenlet`) is the affected component. Versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0 fix the issue.

EPSS

Процентиль: 36%
0.00151
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-20
CWE-269