CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-67508: gardenctl before 2.12.0 (exclusive); +1 more affected products

CVE-2025-67508. CVSS 3.1 base score 8.4 (HIGH, NVD). EPSS 0.00244 (percentile 0.14253), scored 2026-10-06.

Affected technology

gardenctl · before 2.12.0 (exclusive)
linuxfoundation

gardenctl-v2 · < 2.12.0
gardener

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · High privileges required · User interaction required

What an attacker can do

The source says when using non‑POSIX shells such as Fish and PowerShell, versions 2.11.0 and below of gardenctl allow an attacker with administrative privileges for a Gardener project to craft malicious credential values. NVD’s CVSS 3.1 assessment (base score 8.4/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-77
CCR priority
33.7 /100 (P4)
CVSS 3.1
8.4 /10 · CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H · NVD
EPSS
0.00244 · percentile 0.14253 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-67508.html