Improper Authorization in Kubernetes - CVE-2025-4563
Published: June 26, 2025
Vulnerability details
The vulnerability allows a malicious node to bypass dynamic resource allocation authorization checks.
The vulnerability exists due to missing authorization checks in DynamicResourceAllocation feature gate within the NodeRestriction admission controller. A malicious node can create mirror pods that access unauthorized dynamic resources, leading to denial of service or potential privilege escalation.
Affected software
Engineering Lifecycle Management
Netcool Operations Insight
IBM Maximo Application Suite
IBM API Connect
Fedora
Astronomer with IBM
kubernetes1.32
IBM Cloud Pak for Multicloud Management
How to mitigate CVE-2025-4563
Engineering Lifecycle Management - update to 1.3.0
Netcool Operations Insight - update to 1.6.15
IBM Maximo Application Suite - addressed in versions 8.10.33, 8.11.30, 9.0.19, 9.1.8
IBM API Connect - update to 10.0.8.5
Astronomer with IBM - update to 1.1.0
kubernetes1.32 - addressed in versions 1.32.6-1.fc41, 1.32.6-1.fc42, 1.32.6-1.fc43
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
External References
Related Security Bulletins
- Improper authorization in Kubernetes
- Fedora 42 update for kubernetes1.32
- Fedora 41 update for kubernetes1.32
- Astronomer with IBM update for Kubernetes NodeRestriction
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM API Connect
- Fedora 43 update for kubernetes1.32
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Engineering Lifecycle Management on Hybrid Cloud