Arbitrary File Read Vulnerability in KEDA by KEDA Core
CVE-2025-68476
8.2HIGH
What is CVE-2025-68476?
KEDA, a Kubernetes-based Event Driven Autoscaling solution, has a vulnerability that affects the TriggerAuthentication resource used for HashiCorp Vault authentication. In versions before 2.17.3 and 2.18.3, improper path validation allows attackers with certain permissions to exploit this vulnerability. By manipulating requests, it is possible to exfiltrate sensitive files from the node's filesystem, which can include critical system information such as secrets and keys, posing significant risks to system integrity and confidentiality. The issue has been rectified in the latest versions.
Affected Version(s)
keda < 2.17.3 < 2.17.3
keda >= 2.18.0, < 2.18.3 < 2.18.0, 2.18.3
