CVE-2025-64171

HIGH

marin3r <= 0.13.3 - Missing Authorization via DiscoveryServiceCertificate

Title source: llm
STIX 2.1

Description

MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.

Scores

CVSS v4 8.7
EPSS 0.0018
EPSS Percentile 8.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
3scale-sre/marin3r 0 - 0.13.4Go
3scale-sre/marin3r < 0.13.4
Published Nov 06, 2025
Tracked Since Feb 18, 2026