CVE-2025-32445

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 250

Summary

CVE-2025-32445 is a vulnerability affecting Argo Events, an event-driven workflow automation framework for Kubernetes. This issue allows users with permission to create or modify EventSource and Sensor custom resources to gain privileged access to the host system and cluster, bypassing the need for direct administrative privileges. The vulnerability is due to the ability to customize the specification of containers in the corresponding orchestrated pods, including specifying properties such as command, args, and securityContext. A malicious user could exploit this by configuring these properties to gain privileged access to the cluster host. The vulnerability is resolved in version 1.9.6.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share