MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gf93-xccm-5g6j MARIN3R: Cross-Namespace Vulnerability in the Operator
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 06 Nov 2025 00:45:00 +0000

Type Values Removed Values Added
Description MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.
Title MARIN3R: Cross-Namespace Vulnerability in the Operator
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-06T00:23:48.695Z

Reserved: 2025-10-28T21:07:16.439Z

Link: CVE-2025-64171

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-06T01:15:38.493

Modified: 2025-11-06T01:15:38.493

Link: CVE-2025-64171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.