Improper Authorization in Kubernetes - CVE-2025-4563

 

Improper Authorization in Kubernetes - CVE-2025-4563

Published: June 26, 2025


Vulnerability identifier: #VU111971
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:L/SI:L/SA:L]
CVE-ID: CVE-2025-4563
CWE-ID: CWE-285
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a malicious node to bypass dynamic resource allocation authorization checks.

The vulnerability exists due to missing authorization checks in DynamicResourceAllocation feature gate within the NodeRestriction admission controller. A malicious node can create mirror pods that access unauthorized dynamic resources, leading to denial of service or potential privilege escalation. 


Affected software

Kubernetes
Engineering Lifecycle Management
Netcool Operations Insight
IBM Maximo Application Suite
IBM API Connect
Fedora
Astronomer with IBM
kubernetes1.32
IBM Cloud Pak for Multicloud Management

How to mitigate CVE-2025-4563

Install updates from vendor's website.

Kubernetes - addressed in versions 1.32.6, 1.33.2
Engineering Lifecycle Management - update to 1.3.0
Netcool Operations Insight - update to 1.6.15
IBM Maximo Application Suite - addressed in versions 8.10.33, 8.11.30, 9.0.19, 9.1.8
IBM API Connect - update to 10.0.8.5
Astronomer with IBM - update to 1.1.0
kubernetes1.32 - addressed in versions 1.32.6-1.fc41, 1.32.6-1.fc42, 1.32.6-1.fc43
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12

External References

Related Security Bulletins