CVE-2025-47283
vulnerability analysis and mitigation

Overview

Gardener, a service for automated management and operation of Kubernetes clusters, disclosed a critical security vulnerability (CVE-2025-47283) on May 19, 2025. The vulnerability affects versions prior to 1.116.4, 1.117.5, 1.118.2, and 1.119.0, where users with administrative privileges for a Gardener project could potentially gain unauthorized control over seed clusters managing their shoot clusters. This vulnerability impacts all Gardener installations regardless of the public cloud provider used for seed clusters/shoot clusters (GitHub Advisory).

Technical details

The vulnerability has been assigned a CVSS v3.0 base score of 9.9 (Critical) with the following vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The affected component is gardener/gardener (gardenlet). The vulnerability is characterized by improper input validation (CWE-20) and allows privilege escalation through bypassing project secret validation (GitHub Advisory).

Impact

The vulnerability enables users with administrative privileges for a Gardener project to gain unauthorized control over the seed cluster(s) where their shoot clusters are managed. This represents a significant security breach as it affects all Gardener installations regardless of the cloud provider, potentially compromising the entire cluster management infrastructure (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0. Users are strongly advised to upgrade to these fixed versions to mitigate the security risk (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management