MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gf93-xccm-5g6j MARIN3R: Cross-Namespace Vulnerability in the Operator
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 07 Nov 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Thu, 06 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Marin3r
Marin3r marin3r
Vendors & Products Marin3r
Marin3r marin3r

Thu, 06 Nov 2025 00:45:00 +0000

Type Values Removed Values Added
Description MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.
Title MARIN3R: Cross-Namespace Vulnerability in the Operator
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-06T21:17:02.114Z

Reserved: 2025-10-28T21:07:16.439Z

Link: CVE-2025-64171

cve-icon Vulnrichment

Updated: 2025-11-06T21:16:58.262Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-06T01:15:38.493

Modified: 2025-11-06T19:45:09.883

Link: CVE-2025-64171

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-11-06T00:23:48Z

Links: CVE-2025-64171 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-11-06T10:06:43Z

Weaknesses