Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-24784

Опубликовано: 30 янв. 2025
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. The policy group feature, added to by the 1.17.0 release. By being namespaced, the AdmissionPolicyGroup has a well constrained impact on cluster resources. Hence, it’s considered safe to allow non-admin users to create and manage these resources in the namespaces they own. Kubewarden policies can be allowed to query the Kubernetes API at evaluation time; these types of policies are called “context aware“. Context aware policies can perform list and get operations against a Kubernetes cluster. The queries are done using the ServiceAccount of the Policy Server instance that hosts the policy. That means that access to the cluster is determined by the RBAC rules that apply to that ServiceAccount. The AdmissionPolicyGroup CRD allowed the deployment of context aware policies. This could allow an attacker to obtain information about resources that are out of their reac

EPSS

Процентиль: 27%
0.00098
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 4.3
github
около 1 года назад

Kubewarden-Controller information leak via AdmissionPolicyGroup Resource

CVSS3: 4.3
fstec
около 1 года назад

Уязвимость компонента CRD AdmissionPolicyGroup контроллера в кластере Kubernetes kubewarden-controller, позволяющая нарушителю получить несанкционированный доступ на изменение данных или раскрыть защищаемую информацию

suse-cvrf
12 месяцев назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 27%
0.00098
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-285