blob: ace96a95c7a974c2e9fed7777826e38456ace950 [file]
id: GO-2025-4093
modules:
- module: github.com/3scale-sre/marin3r
versions:
- fixed: 0.13.4
vulnerable_at: 0.13.3
summary: 'MARIN3R: Cross-Namespace Vulnerability in the Operator in github.com/3scale-sre/marin3r'
cves:
- CVE-2025-64171
ghsas:
- GHSA-gf93-xccm-5g6j
references:
- advisory: https://github.com/3scale-sre/marin3r/security/advisories/GHSA-gf93-xccm-5g6j
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-64171
- fix: https://github.com/3scale-sre/marin3r/commit/859b14115fde1d67620e645cd1b62e90e30d9981
- fix: https://github.com/3scale-sre/marin3r/commit/c60246a43ae8c0c38dd7267f298d68a121a159fa
- fix: https://github.com/3scale-sre/marin3r/pull/294
source:
id: GHSA-gf93-xccm-5g6j
created: 2025-11-17T13:04:03.070398194-05:00
review_status: UNREVIEWED