gardener/gardener
cpe:2.3:a:gardener:gardener:*:*:*:*:*:*:*
- < v1.116.4
- < v1.117.5
- < v1.118.2
- < v1.119.0
A critical vulnerability has been identified in the gardenlet component of Gardener, affecting versions prior to 1.116.4, 1.117.5, 1.118.2, and 1.119.0. This vulnerability allows users with administrative privileges in a Gardener project to gain control over the seed clusters managing their shoot clusters. The issue is present in all Gardener installations using the gardener/gardener-extension-provider-gcp.
Exploitation of this vulnerability could lead to unauthorized control over seed clusters, allowing manipulation of the shoot clusters managed within them.
Users are advised to update to Gardener versions 1.116.4, 1.117.5, 1.118.2, or 1.119.0.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.