File tree Expand file tree Collapse file tree 2 files changed +96
-0
lines changed Expand file tree Collapse file tree 2 files changed +96
-0
lines changed Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.3.1" ,
3+ "id" : " GO-2025-3915" ,
4+ "modified" : " 0001-01-01T00:00:00Z" ,
5+ "published" : " 0001-01-01T00:00:00Z" ,
6+ "aliases" : [
7+ " CVE-2025-5187" ,
8+ " GHSA-4x4m-3c2p-qppc"
9+ ],
10+ "summary" : " Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes" ,
11+ "details" : " Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes" ,
12+ "affected" : [
13+ {
14+ "package" : {
15+ "name" : " k8s.io/kubernetes" ,
16+ "ecosystem" : " Go"
17+ },
18+ "ranges" : [
19+ {
20+ "type" : " SEMVER" ,
21+ "events" : [
22+ {
23+ "introduced" : " 0"
24+ },
25+ {
26+ "fixed" : " 1.31.12"
27+ },
28+ {
29+ "introduced" : " 1.32.0-alpha.0"
30+ },
31+ {
32+ "fixed" : " 1.32.8"
33+ },
34+ {
35+ "introduced" : " 1.33.0-alpha.0"
36+ },
37+ {
38+ "fixed" : " 1.33.4"
39+ }
40+ ]
41+ }
42+ ],
43+ "ecosystem_specific" : {}
44+ }
45+ ],
46+ "references" : [
47+ {
48+ "type" : " ADVISORY" ,
49+ "url" : " https://github.com/advisories/GHSA-4x4m-3c2p-qppc"
50+ },
51+ {
52+ "type" : " FIX" ,
53+ "url" : " https://github.com/kubernetes/kubernetes/commit/a2d98cac56a0c5cb2d8abc4d087fc00846b3bc0f"
54+ },
55+ {
56+ "type" : " WEB" ,
57+ "url" : " https://github.com/kubernetes/kubernetes/issues/133471"
58+ },
59+ {
60+ "type" : " WEB" ,
61+ "url" : " https://groups.google.com/g/kubernetes-security-announce/c/znSNY7XCztE"
62+ }
63+ ],
64+ "database_specific" : {
65+ "url" : " https://pkg.go.dev/vuln/GO-2025-3915" ,
66+ "review_status" : " REVIEWED"
67+ }
68+ }
Original file line number Diff line number Diff line change 1+ id : GO-2025-3915
2+ modules :
3+ - module : k8s.io/kubernetes
4+ versions :
5+ - fixed : 1.31.12
6+ - introduced : 1.32.0-alpha.0
7+ - fixed : 1.32.8
8+ - introduced : 1.33.0-alpha.0
9+ - fixed : 1.33.4
10+ vulnerable_at : 1.33.3
11+ summary : |-
12+ Kubernetes Nodes can delete themselves by adding an OwnerReference in
13+ k8s.io/kubernetes
14+ cves :
15+ - CVE-2025-5187
16+ ghsas :
17+ - GHSA-4x4m-3c2p-qppc
18+ references :
19+ - advisory : https://github.com/advisories/GHSA-4x4m-3c2p-qppc
20+ - fix : https://github.com/kubernetes/kubernetes/commit/a2d98cac56a0c5cb2d8abc4d087fc00846b3bc0f
21+ - web : https://github.com/kubernetes/kubernetes/issues/133471
22+ - web : https://groups.google.com/g/kubernetes-security-announce/c/znSNY7XCztE
23+ notes :
24+ - cannot resolve symbols : ' reading k8s.io/api/go.mod at revision v0.0.0: unknown revision v0.0.0'
25+ source :
26+ id : GHSA-4x4m-3c2p-qppc
27+ created : 2025-09-17T12:20:23.216846-04:00
28+ review_status : REVIEWED
You can’t perform that action at this time.
0 commit comments