1 results (0.024 seconds)

CVSS: 4.1EPSS: 0%CPEs: 1EXPL: 0

04 Jun 2025 — kro (Kube Resource Orchestrator) 0.1.0 before 0.2.1 allows users (with permission to create or modify ResourceGraphDefinition resources) to supply arbitrary container images. This can lead to a confused-deputy scenario where kro's controllers deploy and run attacker-controlled images, resulting in unauthenticated remote code execution on cluster nodes. • https://github.com/kro-run/kro/compare/v0.2.1...v0.2.2 • CWE-441: Unintended Proxy or Intermediary ('Confused Deputy') •