CVE-2025-47282
vulnerability analysis and mitigation

Overview

A critical security vulnerability (CVE-2025-47282) was discovered in Gardener's External DNS Management prior to version 0.23.6. The vulnerability affects all Gardener installations regardless of the public cloud provider(s) used for the seed clusters/shoot clusters. The affected component is gardener/external-dns-management, which may also be deployed on the seeds by the gardener/gardener-extension-shoot-dns-service extension when enabled. For installations using the shoot-dns-service extension, all versions <= v1.60.0 are affected by this vulnerability (GitHub Advisory, NVD).

Technical details

The vulnerability has been assigned a CVSS v3.0 base score of 9.9 (Critical) with the vector string CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The vulnerability is classified as CWE-20 (Improper Input Validation). The technical assessment indicates network attack vector, low attack complexity, low privileges required, and no user interaction needed for exploitation (GitHub Advisory, Wiz).

Impact

The vulnerability could allow a user with administrative privileges for a Gardener project or a user with administrative privileges for a shoot cluster (including administrative privileges for a single namespace of the shoot cluster) to obtain control over the seed cluster where the shoot cluster is managed (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in version 0.23.6 of Gardener External DNS Management. Users are advised to update to this version or later to mitigate the vulnerability. For users of the gardener-extension-shoot-dns-service, updating beyond version v1.60.0 is required (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management