blob: 796e13864911b4c9ce9cd0d28d214d37df00f512 [file] [log] [blame]
id: GO-2025-3915
modules:
- module: k8s.io/kubernetes
versions:
- fixed: 1.31.12
- introduced: 1.32.0-alpha.0
- fixed: 1.32.8
- introduced: 1.33.0-alpha.0
- fixed: 1.33.4
vulnerable_at: 1.33.3
summary: |-
Kubernetes Nodes can delete themselves by adding an OwnerReference in
k8s.io/kubernetes
cves:
- CVE-2025-5187
ghsas:
- GHSA-4x4m-3c2p-qppc
references:
- advisory: https://github.com/advisories/GHSA-4x4m-3c2p-qppc
- fix: https://github.com/kubernetes/kubernetes/commit/a2d98cac56a0c5cb2d8abc4d087fc00846b3bc0f
- web: https://github.com/kubernetes/kubernetes/issues/133471
- web: https://groups.google.com/g/kubernetes-security-announce/c/znSNY7XCztE
notes:
- cannot resolve symbols: 'reading k8s.io/api/go.mod at revision v0.0.0: unknown revision v0.0.0'
source:
id: GHSA-4x4m-3c2p-qppc
created: 2025-09-17T12:20:23.216846-04:00
review_status: REVIEWED