Severity
6.5MEDIUMNVD
EPSS
0.1%
top 71.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateDec 4

Description

This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NExploitability: 1.2 | Impact: 5.2

Affected Packages3 packages

Debiankubernetes/kubernetes< 1.20.5+really1.20.2-1+3
CVEListV5kubernetes/kubelet<=v1.32.2

🔴Vulnerability Details

6
GHSA
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web2025-12-04
OSV
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes2025-03-25
OSV
CVE-2025-1767: This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node2025-03-13
CVEList
CVE-2025-1767: This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node2025-03-13
GHSA
Kubernetes GitRepo Volume Inadvertent Local Repository Access2025-03-13

📋Vendor Advisories

3
Red Hat
kubelet: GitRepo Volume Inadvertent Local Repository Access2025-03-13
Microsoft
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been depr2025-03-11
Debian
CVE-2025-1767: kubernetes - This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volum...2025
CVE-2025-1767 — Improper Input Validation in Kubernetes | cvebase