CVE-2025-24784
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-24784 is a vulnerability affecting the kubewarden-controller in Kubernetes. In versions prior to 1.21.0, the AdmissionPolicyGroup feature allowed the deployment of context-aware policies, which can perform list and get operations against a Kubernetes cluster. These policies use the ServiceAccount of the Policy Server instance to access the cluster, making the impact of this vulnerability dependent on the privileges granted to the ServiceAccount. By default, the Kubewarden helm chart grants access to cluster-wide resources, including Namespace, Pod, Deployment, and Ingress. An attacker could exploit this vulnerability to obtain information about resources out of their reach by leveraging higher access to the cluster granted to the Policy Server's ServiceAccount. To mitigate this risk, it is recommended to keep the Policy Server's ServiceAccount least privileged. This vulnerability was fixed in version 1.21.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.