Gardener

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    3
    Critical Level Threats
    3
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-67508

    gardenctl is vulnerable to Command Injection when used with non‑POSIX shells

    Last Modified: Mar 17, 2026
    Published: Dec 12, 2025

    CVE-2025-59823

    Gardener providers vulnerable to code injection when Terraformer is used for infrastructure provisioning

    Last Modified: Apr 15, 2026
    Published: Sep 25, 2025

    CVE-2025-47284

    Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalation

    Last Modified: Sep 04, 2025
    Published: May 19, 2025

    CVE-2025-47283

    Bypassing project secret validation can lead to privilege escalation

    Last Modified: Feb 06, 2026
    Published: May 19, 2025

    CVE-2019-12494

    In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET requests from one's own shoot clusters to foreign shoot clusters. This occurs because traffic from shoot to seed via the VPN endpoint is not blocked.

    Last Modified: Nov 21, 2024
    Published: Jun 05, 2019
    Items Per Page
    Gardener Vulnerabilities & Security CVEs | CVE-DB