Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-5187

Опубликовано: 28 авг. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.7

Описание

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

РелизСтатусПримечание
devel

DNE

esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
plucky

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 4%
0.0002
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
redhat
27 дней назад

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

CVSS3: 6.7
nvd
12 дней назад

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

CVSS3: 6.7
debian
12 дней назад

A vulnerability exists in the NodeRestriction admission controller in ...

CVSS3: 6.7
github
12 дней назад

Kubernetes Nodes can delete themselves by adding an OwnerReference

EPSS

Процентиль: 4%
0.0002
Низкий

6.7 Medium

CVSS3