Execution with Unnecessary Privileges
CVE-2025-32445
Summary
A user with permission to create/modify "EventSource" and "Sensor" custom resources can gain privileged access to the host system and cluster, even without having direct administrative privileges. This issue affects github.com/argoproj/argo-events versions prior to 1.9.6.
- LOW
- NETWORK
- HIGH
- CHANGED
- NONE
- LOW
- HIGH
- HIGH
CWE-250 - Execution with Unnecessary Privileges
The software performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
References
Advisory Timeline
- Published