Gardener allows bypassing project secret validation which can lead to privilege escalation
Critical severity GitHub Reviewed Published May 19, 2025 in gardener/gardener • Updated May 19, 2025
Package
github.com/gardener/gardener (Go)
Affected versions
< 1.116.4
>= 1.117.0, < 1.117.5
>= 1.118.0, < 1.118.2
Patched versions
1.116.4
1.117.5
1.118.2
Description
Published to the GitHub Advisory Database May 19, 2025
Reviewed May 19, 2025
Published by the National Vulnerability DatabaseMay 19, 2025
Last updated May 19, 2025
A security vulnerability was discovered in Gardener that could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed.
Am I Vulnerable?
This CVE affects all Gardener installations no matter of the public cloud provider(s) used for the seed clusters/shoot clusters.
Affected Components
gardener/gardenerAffected Versions
Fixed Versions
How do I mitigate this vulnerability?
Update to a fixed version.
References