Unauthorized Cross-Namespace Access in BeyondTrust Provider for External Secrets Operator
CVE-2025-62159
8.7HIGH
What is CVE-2025-62159?
A vulnerability in the BeyondTrust provider implementation for External Secrets Operator allows unauthorized access to Kubernetes secrets across namespaces. This security flaw, present in versions 0.10.1 through 0.19.2, enables the provider to retrieve secrets without validating the proper namespace context, putting sensitive credentials at risk. The issue has been remedied in version 0.20.0, which enforces namespace validation and restricts cross-namespace secret access to the ClusterSecretStore type only. Users are urged to upgrade to the latest version or implement policy engines such as Kyverno or OPA to mitigate potential threats.
Affected Version(s)
external-secrets >= 0.10.1, < 0.20.0