Privilege Chaining Affecting github.com/gardener/gardener/pkg/apiserver/registry/security/credentialsbinding package, versions <1.116.4>=1.117.0 <1.117.5>=1.118.0 <1.118.2


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.1% (30th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMGARDENERGARDENERPKGAPISERVERREGISTRYSECURITYCREDENTIALSBINDING-10260447
  • published1 Jun 2025
  • disclosed19 May 2025
  • creditPeter Sutter

Introduced: 19 May 2025

NewCVE-2025-47283  (opens in a new tab)
CWE-268  (opens in a new tab)

How to fix?

Upgrade github.com/gardener/gardener/pkg/apiserver/registry/security/credentialsbinding to version 1.116.4, 1.117.5, 1.118.2 or higher.

Overview

Affected versions of this package are vulnerable to Privilege Chaining via the project secret validation process. An attacker can escalate privileges and potentially gain control over seed clusters by bypassing the intended security restrictions.

CVSS Base Scores

version 4.0
version 3.1