CVE-2025-64171
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
06/11/2025
Last modified:
06/11/2025
Description
MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH



