CVE-2025-47282
Gardener External DNS Management is an environment to manage external DNS entries for a kubernetes cluster. A security vulnerability was discovered in Gardener's External DNS Management prior to ve...
Affects 0 products across 5 vendors.
Software does not validate or incorrectly validates input, allowing attackers to craft data processed in unintended ways.
Show all 51
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical security vulnerability exists in Gardener's External DNS Management prior to version 0.23.6, allowing users with administrative privileges for a Gardener project or a shoot cluster to potentially manipulate external DNS entries.
BSID: BS-2025-GLOBAL-039710-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-47282?
What is the CVSS score for CVE-2025-47282?
Is CVE-2025-47282 actively exploited?
How do I remediate CVE-2025-47282?
What systems are affected by CVE-2025-47282?
| CVE ID | CVE-2025-47282 |
|---|---|
| BSID | BS-2025-GLOBAL-039710-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Published | 2025-05-19 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
Gardener External DNS Management is an environment to manage external DNS entries for a kubernetes cluster. A security vulnerability was discovered in Gardener's External DNS Management prior to version 0.23.6 that could allow a user with administrative privileges for a Gardener project or a user with administrative privileges for a shoot cluster, including administrative privileges for a single namespace of the shoot cluster, to obtain control over the seed cluster where the shoot cluster is managed. This CVE affects all Gardener installations no matter of the public cloud provider(s) used for the seed clusters/shoot clusters. The affected component is `gardener/external-dns-management`. The `external-dns-management` component may also be deployed on the seeds by the `gardener/gardener-extension-shoot-dns-service` extension when the extension is enabled. In this case, all versions of the `shoot-dns-service` extension `<= v1.60.0` are affected by this vulnerability. Version 0.23.6 of Gardener External DNS Management fixes the issue.
Source: NIST NVD / MITRE CVE Database
An attacker with administrative privileges can exploit this vulnerability to modify DNS records, which could lead to unauthorized redirection of traffic, phishing attacks, or other malicious activities.
Exploitation Likelihood: HIGH
| Vendor | Product | Fixed Version |
|---|---|---|
| Cloud | — | — |
| Gardener | — | — |
| Kubernetes | — | — |
| Project | — | — |
| Seeds | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 57b9a1bd25f4301a22af52e4fbd0ce1d2b5dae9aef1658b9c9c260dc2c16ee56f1d42fd11bfe81cc28506b8ebf8a5e0de14151dce8ecad13908f4a5247127387 |
Critical Severity - Know Your Exposure
A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →