| id: GO-2025-4093 |
| modules: |
| - module: github.com/3scale-sre/marin3r |
| versions: |
| - fixed: 0.13.4 |
| vulnerable_at: 0.13.3 |
| summary: 'MARIN3R: Cross-Namespace Vulnerability in the Operator in github.com/3scale-sre/marin3r' |
| cves: |
| - CVE-2025-64171 |
| ghsas: |
| - GHSA-gf93-xccm-5g6j |
| references: |
| - advisory: https://github.com/3scale-sre/marin3r/security/advisories/GHSA-gf93-xccm-5g6j |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-64171 |
| - fix: https://github.com/3scale-sre/marin3r/commit/859b14115fde1d67620e645cd1b62e90e30d9981 |
| - fix: https://github.com/3scale-sre/marin3r/commit/c60246a43ae8c0c38dd7267f298d68a121a159fa |
| - fix: https://github.com/3scale-sre/marin3r/pull/294 |
| source: |
| id: GHSA-gf93-xccm-5g6j |
| created: 2025-11-17T13:04:03.070398194-05:00 |
| review_status: UNREVIEWED |