MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.
History

Fri, 07 Nov 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Thu, 06 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Marin3r
Marin3r marin3r
Vendors & Products Marin3r
Marin3r marin3r

Thu, 06 Nov 2025 00:45:00 +0000

Type Values Removed Values Added
Description MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.
Title MARIN3R: Cross-Namespace Vulnerability in the Operator
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-06T00:23:48.695Z

Updated: 2025-11-06T21:17:02.114Z

Reserved: 2025-10-28T21:07:16.439Z

Link: CVE-2025-64171

cve-icon Vulnrichment

Updated: 2025-11-06T21:16:58.262Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-06T01:15:38.493

Modified: 2025-11-06T19:45:09.883

Link: CVE-2025-64171

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-11-06T00:23:48Z

Links: CVE-2025-64171 - Bugzilla