GHSA-3wgm-2gw2-vh5m

Suggest an improvement
Source
https://github.com/advisories/GHSA-3wgm-2gw2-vh5m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-3wgm-2gw2-vh5m/GHSA-3wgm-2gw2-vh5m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3wgm-2gw2-vh5m
Aliases
Related
Published
2025-03-13T18:32:22Z
Modified
2025-03-25T20:22:17.630486Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Kubernetes GitRepo Volume Inadvertent Local Repository Access
Details

A security vulnerability was discovered in Kubernetes that could allow a user with create pod permission to exploit gitRepo volumes to access local git repositories belonging to other pods on the same node. This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.

Database specific
{
    "nvd_published_at": "2025-03-13T17:15:36Z",
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2025-03-14T17:30:06Z"
}
References

Affected packages

Go / k8s.io/kubernetes

Package

Name
k8s.io/kubernetes
View open source insights on deps.dev
Purl
pkg:golang/k8s.io/kubernetes

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.32.3