Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-64171

Опубликовано: 06 нояб. 2025
Источник: nvd
EPSS Низкий

Описание

MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.

EPSS

Процентиль: 10%
0.00202
Низкий

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.5
redhat
10 месяцев назад

MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.

github
10 месяцев назад

MARIN3R: Cross-Namespace Vulnerability in the Operator

EPSS

Процентиль: 10%
0.00202
Низкий

Дефекты

CWE-862