CVE-2025-47284: Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalation
A security vulnerability was discovered in the gardenlet component of Gardener. It could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed.
Am I Vulnerable?
This CVE affects all Gardener installations where https://github.com/gardener/gardener-extension-provider-gcp is in use.
Affected Components
- gardener/gardener (gardenlet)
Affected Versions
- < v1.116.4 - < v1.117.5 - < v1.118.2 - < v1.119.0
Fixed Versions
- >= v1.116.4 - >= v1.117.5 - >= v1.118.2 - >= v1.119.0
How do I mitigate this vulnerability?
Update to a fixed version.
Other sources
Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in the gardenlet component of Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0. It could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed. This CVE affects all Gardener installations where gardener/gardener-extension-provider-gcp is in use. Versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0 fix the issue.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47284?
CVE-2025-47284 is considered a critical vulnerability affecting the Gardener gardenlet component.
How do I fix CVE-2025-47284?
To fix CVE-2025-47284, upgrade to Gardener gardenlet versions 1.116.5, 1.117.6, 1.118.3, or 1.119.1 or later.
What versions are vulnerable to CVE-2025-47284?
The vulnerable versions of Gardener gardenlet are all versions prior to 1.116.4, 1.117.5, 1.118.2, and 1.119.0.
What components are affected by CVE-2025-47284?
CVE-2025-47284 specifically impacts the gardenlet component of the Gardener project.
Who is impacted by CVE-2025-47284?
Users with administrative privileges who operate Kubernetes clusters via Gardener are impacted by CVE-2025-47284.