[Git][security-tracker-team/security-tracker][master] Add CVE-2025-0426/kubernetes

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Feb 14 19:55:49 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
32c5a0da by Salvatore Bonaccorso at 2025-02-14T20:54:18+01:00
Add CVE-2025-0426/kubernetes

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -208,7 +208,10 @@ CVE-2025-1270 (Insecure direct object reference (IDOR) vulnerability in Anapi Gr
 CVE-2025-1127 (The vulnerability can be leveraged by an attacker to execute arbitrary ...)
 	NOT-FOR-US: Lexmark
 CVE-2025-0426 (A security issue was discovered in Kubernetes where a large number of  ...)
-	TODO: check
+	- kubernetes 1.20.5+really1.20.2-1
+	NOTE: Server components no longer built since 1.20.5+really1.20.2-1, marking that as fixed version
+	NOTE: The source package itself it still vulnerable, but custom rebuilds are not really a usecase here
+	NOTE: https://www.openwall.com/lists/oss-security/2025/02/13/1
 CVE-2024-13867 (The Listivo - Classified Ads WordPress Theme theme for WordPress is vu ...)
 	NOT-FOR-US: WordPress theme
 CVE-2024-13639 (The Read More & Accordion plugin for WordPress is vulnerable to unauth ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/32c5a0da9ff8b0e392e1b4ef126861660eb3a2c2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/32c5a0da9ff8b0e392e1b4ef126861660eb3a2c2
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250214/bd6d0306/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list