kro Confused Deputy vulnerability
Moderate severity
GitHub Reviewed
Published
Jun 4, 2025
to the GitHub Advisory Database
•
Updated Jun 5, 2025
Package
Affected versions
>= 0.1.0, < 0.2.1
Patched versions
0.2.1
Description
Published by the National Vulnerability Database
Jun 4, 2025
Published to the GitHub Advisory Database
Jun 4, 2025
Reviewed
Jun 5, 2025
Last updated
Jun 5, 2025
kro (Kube Resource Orchestrator) 0.1.0 before 0.2.1 allows users (with permission to create or modify ResourceGraphDefinition resources) to supply arbitrary container images. This can lead to a confused-deputy scenario where kro's controllers deploy and run attacker-controlled images, resulting in unauthenticated remote code execution on cluster nodes.
References