CVE-2025-24784 affects Kubewarden-controller versions prior to 1.21.0, specifically impacting the AdmissionPolicyGroup feature. This vulnerability allows a low-privileged attacker to potentially gain unauthorized access to Kubernetes API resources by leveraging context-aware policies that query the API using the Policy Server's ServiceAccount, which may have higher privileges. Rated as Medium severity (CVSS 4.3), it has a low impact on confidentiality (C:L) and requires low privileges (PR:L) to exploit. While there is no known exploit code or active exploitation, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Kubewarden | Kubewarden-Controller | >= 1.17.0, < 1.21.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.