CVE-2025-64171
vulnerability analysis and mitigation

Overview

CVE-2025-64171 is a cross-namespace vulnerability discovered in the MARIN3R operator that affects all versions prior to v0.13.4. The vulnerability was discovered and disclosed on November 4, 2025. The issue affects the DiscoveryServiceCertificate functionality in the MARIN3R operator, specifically impacting Kubernetes deployments using this component (GitHub Advisory, Miggo).

Technical details

The vulnerability exists in the getIssuerCertificate function of the CertificateProvider struct, located in internal/pkg/reconcilers/operator/discoveryservicecertificate/providers/marin3r/crud.go. The function failed to validate that the namespace of the referenced secret matched the namespace of the DiscoveryServiceCertificate resource, allowing unauthorized cross-namespace access. The issue is classified as CWE-862 (Missing Authorization) (Miggo).

Impact

When exploited, this vulnerability allows users with permission to create DiscoveryServiceCertificate resources in one namespace to indirectly read Secrets from other namespaces, effectively bypassing Kubernetes RBAC security boundaries. This represents a significant security breach in the isolation between namespaces (GitHub Advisory).

Mitigation and workarounds

A patch has been released in version v0.13.4 which adds validation to ensure namespaces match before allowing access to Secrets. As a temporary workaround, organizations are advised to restrict DiscoveryServiceCertificate create permissions to cluster administrators only until the patched version can be deployed (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management