Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gf93-xccm-5g6j | MARIN3R: Cross-Namespace Vulnerability in the Operator |
Fri, 07 Nov 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 06 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Nov 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Marin3r
Marin3r marin3r |
|
| Vendors & Products |
Marin3r
Marin3r marin3r |
Thu, 06 Nov 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4. | |
| Title | MARIN3R: Cross-Namespace Vulnerability in the Operator | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-06T21:17:02.114Z
Reserved: 2025-10-28T21:07:16.439Z
Link: CVE-2025-64171
Updated: 2025-11-06T21:16:58.262Z
Status : Deferred
Published: 2025-11-06T01:15:38.493
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-64171
OpenCVE Enrichment
Updated: 2025-11-06T10:06:43Z
Github GHSA