Gardener allows metadata injection for a project secret which can lead to privilege escalation
Critical severity
GitHub Reviewed
Published
May 19, 2025
in
gardener/gardener
•
Updated May 19, 2025
Package
Affected versions
< 1.116.4
>= 1.117.0, < 1.117.5
>= 1.118.0, < 1.118.2
Patched versions
1.116.4
1.117.5
1.118.2
Description
Published by the National Vulnerability Database
May 19, 2025
Published to the GitHub Advisory Database
May 19, 2025
Reviewed
May 19, 2025
Last updated
May 19, 2025
A security vulnerability was discovered in the
gardenlet
component of Gardener. It could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed.Am I Vulnerable?
This CVE affects all Gardener installations where https://github.com/gardener/gardener-extension-provider-gcp is in use.
Affected Components
gardener/gardener
(gardenlet
)Affected Versions
Fixed Versions
How do I mitigate this vulnerability?
Update to a fixed version.
References