CVE-2025-1767 — Improper Input Validation in Kubernetes
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 71.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 13
Latest updateDec 4
Description
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NExploitability: 1.2 | Impact: 5.2
Affected Packages3 packages
🔴Vulnerability Details
6GHSA▶
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web↗2025-12-04
OSV▶
CVE-2025-1767: This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node↗2025-03-13
CVEList▶
CVE-2025-1767: This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node↗2025-03-13
📋Vendor Advisories
3Microsoft▶
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been depr↗2025-03-11
Debian▶
CVE-2025-1767: kubernetes - This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volum...↗2025