CVE-2025-62159

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-62159
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62159.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-62159
Aliases
  • GHSA-vf79-2pjx-phpp
Downstream
Published
2025-10-10T22:23:19.071Z
Modified
2025-12-05T10:21:09.984174Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
External Secrets Operator's BeyondTrust Provider has Insecure Secret Retrieval
Details

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. A vulnerability was discovered in the BeyondTrust provider implementation for External Secrets Operator versions 0.10.1 through 0.19.2. The provider previously retrieved Kubernetes secrets directly, without validating the namespace context or the type of secret store. This allowed unauthorized cross-namespace secret access, violating security boundaries and potentially exposing sensitive credentials. In version 0.20.0, the provider code was updated to use the resolvers.SecretKeyRef utility, which enforces namespace validation and only allows cross-namespace access for ClusterSecretStore types. This ensures secrets are only retrieved from the correct namespace, mitigating the risk of unauthorized access. All users should upgrade to the latest version containing this fix. As a workaround, use a policy engine such as Kyverno or OPA to prevent using BeyondTrust provider and/or validate the (Cluster)SecretStore and ensure the namespace may only be set when using a ClusterSecretStore.

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62159.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/external-secrets/external-secrets

Affected ranges

Type
GIT
Repo
https://github.com/external-secrets/external-secrets
Events

Affected versions

helm-chart-0.*

helm-chart-0.10.1
helm-chart-0.10.2
helm-chart-0.10.6
helm-chart-0.14.1
helm-chart-0.14.2
helm-chart-0.15.1
helm-chart-0.16.0
helm-chart-0.17.0
helm-chart-0.18.0-rc1
helm-chart-0.19.2

v0.*

v0.1.0-esoctl
v0.1.0-render
v0.10.1
v0.10.2
v0.10.3
v0.10.4
v0.10.5
v0.10.6
v0.10.7
v0.11.0
v0.12.0
v0.12.1
v0.13.0
v0.14.0
v0.14.1
v0.14.2
v0.14.3
v0.14.4
v0.15.0
v0.15.1
v0.16.0
v0.16.1
v0.16.2
v0.17.0
v0.17.1-rc1
v0.18.0
v0.18.0-rc1
v0.18.1
v0.18.2
v0.19.0
v0.19.1
v0.19.2

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62159.json"