#VU111971 Improper Authorization in Kubernetes - CVE-2025-4563
Published: June 26, 2025
Kubernetes
Kubernetes
Description
The vulnerability allows a malicious node to bypass dynamic resource allocation authorization checks.
The vulnerability exists due to missing authorization checks in DynamicResourceAllocation feature gate within the NodeRestriction admission controller. A malicious node can create mirror pods that access unauthorized dynamic resources, leading to denial of service or potential privilege escalation.