PT-2025-17879 · Cncf · K3S
F1Vet
·
Published
2025-04-25
·
Updated
2025-05-08
·
CVE-2025-46599
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CNCF K3s versions 1.32 through 1.32.4-rc1+k3s1
Description
The issue arises from a Kubernetes kubelet configuration change, which in certain situations, sets ReadOnlyPort to 10255. This could potentially allow unauthenticated access to this port, exposing credentials, particularly in default K3s online installation behaviors.
Recommendations
For CNCF K3s versions 1.32 through 1.32.4-rc1+k3s1, update to version 1.32.4-rc1+k3s1 or later to resolve the issue. As a temporary workaround, consider restricting access to port 10255 to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
K3S