A security vulnerability was discovered in Gardener that could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed.
Am I Vulnerable?
This CVE affects all Gardener installations no matter of the public cloud provider(s) used for the seed clusters/shoot clusters.
Affected Components
- gardener/gardener
Affected Versions
- < v1.116.4 - < v1.117.5 - < v1.118.2 - < v1.119.0
Fixed Versions
- >= v1.116.4 - >= v1.117.5 - >= v1.118.2 - >= v1.119.0
How do I mitigate this vulnerability?
Update to a fixed version.