Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-1767

Опубликовано: 13 мар. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.

A flaw was found in Kubernetes. This vulnerability allows a user with create pod permissions to exploit gitRepo volumes to access local git repositories belonging to other pods on the same node.

Отчет

This vulnerability is rated as moderate severity because it affects Kubernetes clusters using the deprecated in-tree gitRepo volume feature, which allows cloning git repositories from other pods within the same node. Within regulated environments, a combination of the following controls acts as a significant barrier to successfully exploiting a CWE-280: Improper Handling of Insufficient Permissions or Privileges vulnerability and therefore downgrades the severity of this particular CVE from Moderate to Low. Access enforcement and least privilege controls ensure that only authorized users and processes can access sensitive services, reducing the risk of unauthorized privilege use. Role-based access control (RBAC) and defined security boundaries at the platform level prevent privilege escalation by isolating workloads and enforcing permission policies. Process isolation further contains unauthorized actions within individual containers. Configuration management ensures consistent application of access policies across updates and deployments. Additionally, runtime monitoring, audit logging, and malicious code protection detect and respond to unauthorized access attempts, minimizing the likelihood and impact of insufficient privilege enforcement.

Меры по смягчению последствий

This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/platform-resource-runner-rhel8Fix deferred
Red Hat Ansible Automation Platform 2automation-controllerFix deferred
Red Hat Discovery 1discovery-server-containerFix deferred
Red Hat Enterprise Linux 10fence-agentsFix deferred
Red Hat Enterprise Linux 9fence-agentsFix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-kf-notebook-controller-rhel8Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-api-server-v2-rhel8Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-driver-rhel8Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-launcher-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-280
https://bugzilla.redhat.com/show_bug.cgi?id=2351269kubelet: GitRepo Volume Inadvertent Local Repository Access

EPSS

Процентиль: 12%
0.00043
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
5 месяцев назад

This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.

CVSS3: 6.5
nvd
5 месяцев назад

This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.

CVSS3: 6.5
debian
5 месяцев назад

This CVE only affects Kubernetes clusters that utilize the in-tree git ...

CVSS3: 6.5
github
5 месяцев назад

Kubernetes GitRepo Volume Inadvertent Local Repository Access

CVSS3: 6.5
fstec
5 месяцев назад

Уязвимость функции gitRepo программного средства управления кластерами виртуальных машин Kubernetes, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 12%
0.00043
Низкий

6.5 Medium

CVSS3