8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.
AI Analysis
Cross-namespace secret access vulnerability in MARIN3R's DiscoveryServiceCertificate
Basic Information
ID
CVE-2025-64171
Source
GitHub_M
Published
Nov 6, 2025 at 00:23
Affected Product
Vendor
3scale-sre
Product
marin3r
Version
< 0.13.4
Affected Versions
3scale-sre marin3r < 0.13.4
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
3scale-sre
Product
MARIN3R
Version
0.13.3 and below