CVE-2025-1767
MEDIUMKubernetes - Improper Input Validation in gitRepo Volume
Title source: llmDescription
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.
References (3)
Core 3
Core References
Issue Tracking
https://github.com/kubernetes/kubernetes/pull/130786
Scores
CVSS v3
6.5
EPSS
0.0052
EPSS Percentile
39.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-20
Status
published
Products (2)
k8s.io/kubernetes
0Go
Kubernetes/Kubelet
<=v1.32.2
Published
Mar 13, 2025
Tracked Since
Feb 18, 2026