CVE-2025-46599: Medium severity k3s vulnerability
CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For example, the default behavior of a K3s online installation might allow unauthenticated access to this port, exposing credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46599?
CVE-2025-46599 is considered a critical vulnerability due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2025-46599?
To fix CVE-2025-46599, upgrade K3s to version 1.32.4-rc1+k3s1 or later, where the ReadOnlyPort is properly configured.
What are the risks associated with CVE-2025-46599?
The risks of CVE-2025-46599 include exposing potentially sensitive credentials and information to unauthorized users due to incorrect kubelet configuration.
Which versions of K3s are affected by CVE-2025-46599?
CVE-2025-46599 affects K3s versions prior to 1.32.4-rc1+k3s1.
Is there a workaround for CVE-2025-46599 if immediate patching isn't possible?
Yes, temporarily disabling the ReadOnlyPort can serve as a workaround until a proper upgrade can be applied.