CVE-2025-47282 Details
Description
Gardener External DNS Management is an environment to manage external DNS entries for a kubernetes cluster. A security vulnerability was discovered in Gardener's External DNS Management prior to version 0.23.6 that could allow a user with administrative privileges for a Gardener project or a user with administrative privileges for a shoot cluster, including administrative privileges for a single namespace of the shoot cluster, to obtain control over the seed cluster where the shoot cluster is managed. This CVE affects all Gardener installations no matter of the public cloud provider(s) used for the seed clusters/shoot clusters. The affected component is `gardener/external-dns-management`. The `external-dns-management` component may also be deployed on the seeds by the `gardener/gardener-extension-shoot-dns-service` extension when the extension is enabled. In this case, all versions of the `shoot-dns-service` extension `<= v1.60.0` are affected by this vulnerability. Version 0.23.6 of Gardener External DNS Management fixes the issue.
A critical vulnerability exists in Gardener External DNS Management versions prior to 0.23.6, allowing users with administrative rights in a Gardener project or a shoot cluster (including single namespace admin rights) to gain control over the seed cluster managing the shoot cluster. This issue affects all Gardener installations, regardless of the public cloud provider used for seed or shoot clusters. The vulnerability arises from improper management of administrative privileges, potentially leading to unauthorized control over the seed cluster.
Users are advised to update Gardener External DNS Management to version 0.23.6 or later. If the 'gardener/gardener-extension-shoot-dns-service' extension is enabled, update to version 1.60.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 19, 2025CISA-ADP
Assessed May 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gardener/external-dns-management/security/advisories/GHSA-xwgg-m7fx-83wx | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gardener/external-dns-management | < 0.23.6 (semver) |
CPE
Remediation
| |
| gardener/gardener-extension-shoot-dns-service | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2025 | New CVE Received | [email protected] |
Volerion