openwall.com
http://www.openwall.com/lists/oss-security/2025/03/13/9 CVE-2025-1767
MEDIUM
Kubernetes GitRepo Volume Inadvertent Local Repository Access
Record summary
CVE-2025-1767 has a selected CVSS score of 6.5 (medium).
Description
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 13, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
KubeletBrowse Kubernetes / KubeletDefault status: unaffected | CVE List | <=v1.32.2 | affected |
k8s.io/kubernetesBrowse Go / k8s.io/kubernetes | GitHub Advisory | Through 1.32.3 | affected |
References
5github.com
https://github.com/kubernetes/kubernetes github.com
https://github.com/kubernetes/kubernetes/pull/130786 groups.google.com
https://groups.google.com/g/kubernetes-security-announce/c/19irihsKg7s nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-1767