CVE-2025-64171
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-06

Last updated on: 2025-11-06

Assigner: GitHub, Inc.

Description
MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-06
Last Modified
2025-11-06
Generated
2026-06-16
AI Q&A
2025-11-06
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
3scale-sre marin3r 0.13.3
3scale-sre marin3r 0.13.4
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in MARIN3R versions 0.13.3 and below, where the DiscoveryServiceCertificate component allows users to bypass Role-Based Access Control (RBAC) and access secrets in namespaces they are not authorized to access. Essentially, it is a cross-namespace secret access vulnerability that lets unauthorized users retrieve sensitive information from other namespaces.

Impact Analysis

The vulnerability can lead to unauthorized access to sensitive secrets across different namespaces in a Kubernetes environment. This can result in exposure of confidential data, potential privilege escalation, and compromise of the security boundaries intended by RBAC policies, thereby increasing the risk of data breaches and system compromise.

Mitigation Strategies

Upgrade MARIN3R to version 0.13.4 or later, as this version fixes the cross-namespace secret access vulnerability in the DiscoveryServiceCertificate component.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-64171. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart