A security vulnerability was discovered in the gardenlet
component of Gardener. It could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed.
This CVE affects all Gardener installations where https://github.com/gardener/gardener-extension-provider-gcp is in use.
gardener/gardener
(gardenlet
)Update to a fixed version.
{ "nvd_published_at": "2025-05-19T19:15:51Z", "cwe_ids": [ "CWE-150" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2025-05-19T21:09:32Z" }