VDB
GO-2025-3522
GO-2025-3522
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes
Risk Scores
CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| k8s.io | kubernetes | 0, 1.31.0-alpha.0, 1.32.0-alpha.0 |
Timeline
- Mar 25, 2025 CVE Published
- Feb 4, 2026 CVE Updated
References
- https://github.com/advisories/GHSA-vv39-3w5q-974q advisory
- http://www.openwall.com/lists/oss-security/2025/01/16/1 url
- https://groups.google.com/g/kubernetes-security-announce/c/9C3vn6aCSVg url
- https://github.com/kubernetes/kubernetes/commit/45f4ccc2153bbb782253704cbe24c05e22b5d60c fix
- https://github.com/kubernetes/kubernetes/commit/5fe148234f8ab1184f26069c4f7bef6c37efe347 fix
- https://github.com/kubernetes/kubernetes/commit/75c83a6871dc030675288c6d63c275a43c2f0d55 fix
- https://github.com/kubernetes/kubernetes/commit/fb0187c2bf7061258bb89891edb1237261eb7abc fix
- https://github.com/kubernetes/kubernetes/issues/129654 discussion