icon

We found results for “

CVE-2025-47284

Good to know:

icon

Date: May 19, 2025

Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in the "gardenlet" component of Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0. It could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed. This CVE affects all Gardener installations where gardener/gardener-extension-provider-gcp is in use. Versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0 fix the issue.

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Escape, Meta, or Control Sequences

CWE-150

Top Fix

icon

Upgrade Version

Upgrade to version github.com/gardener/gardener - v1.116.4;github.com/gardener/gardener - v1.117.5;github.com/gardener/gardener - v1.118.2;github.com/gardener/gardener - v1.116.4

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us