CVE-2025-23260

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/06/2025
Last modified:
15/12/2025

Description

NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using the ServiceAccount attached to the ClusterRole. A successful exploit of this vulnerability may lead to information disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nvidia:aistore:*:*:*:*:*:kubernetes:*:* 2.3.0 (excluding)


References to Advisories, Solutions, and Tools