Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Elliott-Beach

#41064of 56,330
7.1Total CVSS
Vulnerabilities · 1
PT-2025-38069
7.1
2025-09-15
Unknown · Kubernetes Client · CVE-2025-9708
**Name of the Vulnerable Software and Affected Versions** Kubernetes C# client versions prior to 17.0.14 **Description** A flaw exists in the Kubernetes C# client's certificate validation logic, allowing it to accept certificates from any Certificate Authority (CA) without proper trust chain verification. This can enable a malicious actor to present a forged certificate, potentially intercepting or manipulating communication with the Kubernetes API server, leading to man-in-the-middle attacks and API impersonation. **Recommendations** Kubernetes C# client versions prior to 17.0.14 should be updated to version 17.0.14 or later. As an alternative, move the CA certificates into the system trust store instead of specifying them in the kubeconfig file.