CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-48710: kro (Kube Resource Orchestrator) 0.1.0 before 0.2.1 allows users (with permission to create or modify ResourceGraphDefinition resources) to supply...

4.1 CVSS

Description

kro (Kube Resource Orchestrator) 0.1.0 before 0.2.1 allows users (with permission to create or modify ResourceGraphDefinition resources) to supply arbitrary container images. This can lead to a confused-deputy scenario where kro's controllers deploy and run attacker-controlled images, resulting in unauthenticated remote code execution on cluster nodes.

Classification

CVE ID: CVE-2025-48710

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.1

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N

Problem Types

CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')

Affected Products

Vendor: kro.run

Product: kro

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.1% (probability of being exploited)

EPSS Percentile: 28.46% (scored less or equal to compared to others)

EPSS Date: 2025-06-26 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-48710
https://github.com/kro-run/kro/compare/v0.2.1...v0.2.2
https://orca.security/resources/blog/kubernetes-crd-abstraction-risks-kro/

Timeline