Code Injection Vulnerability in Gardener Extensions for Multiple Cloud Providers
CVE-2025-59823
What is CVE-2025-59823?
A vulnerability exists in Gardener Extensions that could potentially allow a user with administrative privileges to execute code via injection. This flaw specifically affects users of AWS, Azure, OpenStack, and GCP providers with versions below the specified thresholds. By exploiting this issue, an attacker could gain control over critical components of the Kubernetes cluster management system. The vulnerability is particularly concerning for installations using Terraformer for infrastructure provisioning. Updated versions have been released to mitigate this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
gardener-extension-provider-aws < 1.64.0 < 1.64.0
gardener-extension-provider-aws < 1.55.0 < 1.55.0
gardener-extension-provider-aws < 1.49.0 < 1.49.0
References
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
