CVE-2025-1767
Wolfi vulnerability analysis and mitigation

Overview

CVE-2025-1767 is a security vulnerability discovered in Kubernetes that affects clusters utilizing the in-tree gitRepo volume feature. The vulnerability was disclosed on March 13, 2025, and allows users with create pod permission to exploit gitRepo volumes to access local git repositories belonging to other pods on the same node (Kubernetes Issue, OSS Security).

Technical details

The vulnerability has been rated as Medium severity with a CVSS v3.1 score of 6.5 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N). It specifically affects the kubelet component in all versions of Kubernetes. The vulnerability exists in the in-tree gitRepo volume feature, which has been deprecated and will not receive security updates upstream (OSS Security).

Impact

The vulnerability allows attackers with pod creation privileges to access local git repositories belonging to other pods running on the same node, potentially leading to unauthorized access to sensitive repository data (OSS Security).

Mitigation and workarounds

To mitigate this vulnerability, administrators should use an init container to perform git clone operations and then mount the directory into the Pod's container. Additionally, the use of gitRepo volumes can be restricted using ValidatingAdmissionPolicy or through Restricted pod security standard policy. A CEL expression can be used to reject gitRepo volumes: has(object.spec.volumes) || !object.spec.volumes.exists(v, has(v.gitRepo)) (OSS Security).

Additional resources


SourceThis report was generated using AI

Related Wolfi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66471HIGH8.9
  • PythonPython
  • py3-urllib3
NoYesDec 05, 2025
CVE-2025-66418HIGH8.9
  • PythonPython
  • python-urllib3
NoYesDec 05, 2025
CVE-2025-66564HIGH7.5
  • Datadog AgentDatadog Agent
  • cosign
NoYesDec 04, 2025
CVE-2025-66490MEDIUM6.9
  • WolfiWolfi
  • traefik-3
NoYesDec 09, 2025
CVE-2025-66491MEDIUM5.9
  • WolfiWolfi
  • traefik
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management