MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.
History

Thu, 06 Nov 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Marin3r
Marin3r marin3r
Vendors & Products Marin3r
Marin3r marin3r

Thu, 06 Nov 2025 00:45:00 +0000

Type Values Removed Values Added
Description MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.
Title MARIN3R: Cross-Namespace Vulnerability in the Operator
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-06T00:23:48.695Z

Reserved: 2025-10-28T21:07:16.439Z

Link: CVE-2025-64171

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-06T01:15:38.493

Modified: 2025-11-06T01:15:38.493

Link: CVE-2025-64171

cve-icon Redhat

No data.