CVE-2025-67508 is a high-severity vulnerability affecting gardenctl versions 2.11.0 and below, a command-line client for Gardener. It allows an attacker with administrative privileges within a Gardener project to craft malicious credential values in infrastructure Secret objects. These forged credentials can break out of their intended string context when processed by non-POSIX shells like Fish or PowerShell used by Gardener service operators, leading to potential compromise. The vulnerability has a CVSS score of 8.0 (High), indicating a network attack vector, high attack complexity, and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.12.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:gardenctl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.