Vulnerability in Gardener External DNS Management Affecting Kubernetes Clusters
CVE-2025-47282
9.9CRITICAL
What is CVE-2025-47282?
A security risk has been identified in Gardener External DNS Management that permits users with elevated administrative privileges to gain unauthorized control over the seed cluster managing their Kubernetes shoot cluster. This vulnerability impacts all installations of Gardener's DNS management solution regardless of the cloud provider in use. The issue arises from the configuration of the 'gardener/external-dns-management' component and is exacerbated if the 'gardener/gardener-extension-shoot-dns-service' extension is enabled. All users are advised to update to version 0.23.6 or later of Gardener External DNS Management to mitigate this risk.
Affected Version(s)
external-dns-management < 0.23.6
