Metrics
Affected Vendors & Products
Thu, 04 Sep 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gardener:gardener:*:*:*:*:*:*:*:* | |
Metrics |
cvssV3_1
|
Tue, 20 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 19 May 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in the `gardenlet` component of Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0. It could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed. This CVE affects all Gardener installations where gardener/gardener-extension-provider-gcp is in use. Versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0 fix the issue. | |
Title | Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalation | |
Weaknesses | CWE-150 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-20T13:03:34.493Z
Reserved: 2025-05-05T16:53:10.373Z
Link: CVE-2025-47284

Updated: 2025-05-20T13:03:31.593Z

Status : Analyzed
Published: 2025-05-19T19:15:51.870
Modified: 2025-09-04T18:38:28.530
Link: CVE-2025-47284

No data.

Updated: 2025-06-23T19:31:58Z