Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2025-24376 — kubewarden-controller

🟡 CVSS 6.5 — Medium ✅ No Known Exploit CWE-155 NVD
6.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

KubeWarden's AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter PolicyReport resources

Impact

By design, AdmissionPolicy and AdmissionPolicyGroup can evaluate only namespaced resources. The resources to be evaluated are determined by the rules provided by the user when defining the policy.

There might be Kubernetes namespaced resources that should not be validated by AdmissionPolicy and by the AdmissionPolicyGroup policies because of their sensitive nature.

For example, PolicyReport are namespaced resources that contain the list of non compliant objects found inside of a namespace. See [this section](https://docs.kubewarden.io/explanations/audit-scanner/policy-reports) of Kubewarden’s documentation for more details about PolicyReport resources.

An attacker can use either an AdmissionPolicy or an AdmissionPolicyGroup to prevent the creation and update of PolicyReport objects to hide non-compliant resources.

Moreover, the same attacker might use a mutating AdmissionPolicy to alter the contents of the PolicyReport created inside of the namespace.

Patches

Starting from the 1.21.0 release, the validation rules applied to AdmissionPolicy and AdmissionPolicyGroup have been tightened to prevent them from validating sensitive types of namespaced resources.

The new validation will also restrict the usage of wildcards when defining apiGroups and resources rules for AdmissionPolicy and AdmissionPolicyGroup objects.

Workarounds

On clusters running Kubewarden < 1.21.0, the following Kubewarden policy can be applied to prevent the creation of AdmissionPolicy and AdmissionPolicyGroup resources that interact with PolicyReport resources:

```yaml

apiVersion: policies.kubewarden.io/v1

kind: ClusterAdmissionPolicy

metadata:

name: "deny-interaction-with-policyreport"

spec:

module: registry://ghcr.io/kubewarden/policies/cel-policy:latest

settings:

variables:

  • name: hasWildcardInsideOfApiGroup

expression: "object.spec.rules.exists(r, r.apiGroups.exists(ag, ag == '*'))"

  • name: hasWildcardInsideOfResources

expression: "object.spec.rules.exists(r, r.resources.exists(ag, ag == '*' || ag == '*/*' || ag == 'policyreports/*'))"

  • name: dealsWithPolicyReportApiGroup

expression: "object.spec.rules.exists(r, r.apiGroups.exists(ag, ag == 'wgpolicyk8s.io'))"

  • name: dealsWithPolicyReportResource

expression: "object.spec.rules.exists(r, r.resources.exists(ag, ag == 'policyreports' || ag == 'policyreports/'))"

  • name: isPendingDeletion

expression: "has(object.metadata.deletionTimestamp)"

validations:

  • expression: |

!( variables.hasWildcardInsideOfApiGroup ||

variables.hasWildcardInsideOfResources ||

variables.dealsWithPolicyReportResource ||

variables.dealsWithPolicyReportApiGroup

) || variables.isPendingDeletion

message: "cannot target PolicyReport resources or use wildcards in apiGroups or resources"

rules:

  • apiGroups: ["policies.kubewarden.io"]

apiVersions: ["v1"]

operations: ["CREATE", "UPDATE"]

resources: ["admissionpolicies", "admissionpolicygroups"]

mutating: false

backgroundAudit: true

```

For more information

If you have any questions or comments about this advisory you can contact the Kubewarden team using the procedures described under the “[security disclosure](https://docs.kubewarden.io/disclosure)“ guidelines of the Kubewarden project.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity low, availability low.

CVSS metrics in full

The score comes from this vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

  • Attack vector: Network — reachable from anywhere that can route to the service.
  • Attack complexity: Low — the attack works reliably, with no preparation.
  • Privileges required: None — an unauthenticated stranger can try it.
  • User interaction: None — nobody has to be tricked into anything.
  • Scope: Unchanged — the damage stays inside the vulnerable component.
  • Confidentiality impact: None.
  • Integrity impact: Low — limited, and the attacker does not choose what is affected.
  • Availability impact: Low — limited, and the attacker does not choose what is affected.

Weakness class

CVE-2025-24376 is classified as CWE-155: Improper Neutralization of Wildcards or Matching Symbols. The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as wildcards or matching symbols when they are sent to a downstream component.

Affected software

CVE-2025-24376 is recorded against 2 packages.

  • github.com/kubewarden/kubewarden-controller
  • unknown

Timeline and source

Published on 4 February 2025 and last revised on 3 March 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

github.com (Advisory)
nvd.nist.gov (Advisory)
github.com (Fix)

Other advisories for this package

github.com/kubewarden/kubewarden-controller has other advisories on record. If you are patching this one, these are worth checking on the same host:

Same weakness in other software

These advisories are the same class of weakness (CWE-155: Improper Neutralization of Wildcards or Matching Symbols) in other software:

Details

Severity Medium
CVSS Score 6.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CWE CWE-155
Public Exploit ✅ No
Source NVD
Published 2025-02-04
Updated 2026-08-20
Modified 2026-03-03

Affected Packages

Software From version Fixed in
github.com/kubewarden/kubewarden-controller
unknown

Similar Threats

Vulnerability Monitoring

Track new vulnerabilities in kubewarden-controller

CVE-2025-24376 is rated CVSS 6.5 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.

Set Up Free Alerts →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2025