PT-2025-52724 · Keda · Keda
Jorge Turrado
·
Published
2025-12-22
·
Updated
2026-01-08
·
CVE-2025-68476
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
KEDA versions prior to 2.17.3
KEDA versions prior to 2.18.3
Description
KEDA is a Kubernetes-based Event Driven Autoscaling component. A flaw exists in KEDA that could allow an attacker with permissions to create or modify a TriggerAuthentication resource to read arbitrary files from the node's filesystem where the KEDA pod resides. This is due to insufficient path validation when loading the Service Account Token specified in
spec.hashiCorpVault.credential.serviceAccount. The attacker can direct the file's content to a server they control as part of the Vault authentication request, potentially exfiltrating sensitive system information like secrets, keys, or files such as /etc/passwd. This issue affects any KEDA resource using TriggerAuthentication with HashiCorp Vault authentication.Recommendations
Update KEDA to version 2.17.3 or later.
Update KEDA to version 2.18.3 or later.
Exploit
Fix
Incorrect Authorization
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keda