{ "schema_version": "1.4.0", "id": "GHSA-3hw7-qj9h-r835", "modified": "2026-02-06T18:56:41Z", "published": "2025-05-19T19:15:03Z", "aliases": [ "CVE-2025-47283" ], "summary": "Gardener allows bypassing project secret validation which can lead to privilege escalation", "details": "A security vulnerability was discovered in Gardener that could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed.\n\n### Am I Vulnerable?\n\nThis CVE affects all Gardener installations no matter of the public cloud provider(s) used for the seed clusters/shoot clusters.\n\n### Affected Components\n\n- `gardener/gardener`\n\n### Affected Versions\n\n- < v1.116.4\n- < v1.117.5\n- < v1.118.2\n- < v1.119.0\n\n### Fixed Versions\n\n- >= v1.116.4\n- >= v1.117.5\n- >= v1.118.2\n- >= v1.119.0\n\n### How do I mitigate this vulnerability?\n\nUpdate to a fixed version.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], "affected": [ { "package": { "ecosystem": "Go", "name": "github.com/gardener/gardener" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "fixed": "1.116.4" } ] } ] }, { "package": { "ecosystem": "Go", "name": "github.com/gardener/gardener" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "1.117.0" }, { "fixed": "1.117.5" } ] } ] }, { "package": { "ecosystem": "Go", "name": "github.com/gardener/gardener" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "1.118.0" }, { "fixed": "1.118.2" } ] } ] } ], "references": [ { "type": "WEB", "url": "https://github.com/gardener/gardener/security/advisories/GHSA-3hw7-qj9h-r835" }, { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47283" }, { "type": "WEB", "url": "https://github.com/gardener/gardener/commit/924b1575aae052bcda5a51fac8594d38fa3c41b0" }, { "type": "WEB", "url": "https://github.com/gardener/gardener/commit/b89cf2cd5067e82f364063d5241af73650a6e11d" }, { "type": "WEB", "url": "https://github.com/gardener/gardener/commit/bbd19b1dd3a31843d7b820172d37f75298dfaf8b" }, { "type": "WEB", "url": "https://github.com/gardener/gardener/commit/cf4e9887d83902216b85609caf563f7a9dd2de00" }, { "type": "PACKAGE", "url": "https://github.com/gardener/gardener" } ], "database_specific": { "cwe_ids": [ "CWE-20", "CWE-269" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2025-05-19T19:15:03Z", "nvd_published_at": "2025-05-19T19:15:51Z" } }