CVE-2019-12494: Gardener
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET requests from one's own shoot clusters to foreign shoot clusters. This occurs because traffic from shoot to seed via the VPN endpoint is not blocked.
Affected products
- Gardener Gardener: before 0.20.0 (fixed in 0.20.0)
Published 2019-06-05. Last modified 2026-06-17.