CVE Explorer
CVE-2025-61916
Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primary impact is allowing users to fetch data from a remote URL. This data can be then injected into spinnaker pipelines via helm or other methods to extract things LIKE idmsv1 authentication data. This also includes calling internal spinnaker API's via a get and similar endpoints. Further, depending upon the artifact in que
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-20","description":"CWE-20: Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8e706824218718353401f44d308b6cdd700b90c60425111bb8b7190df4f90b8c · sha256:297cf934af64a09b… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8e706824218718353401f44d308b6cdd700b90c60425111bb8b7190df4f90b8c · sha256:297cf934af64a09b… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-523","description":"CWE-523: Unprotected Transport of Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8e706824218718353401f44d308b6cdd700b90c60425111bb8b7190df4f90b8c · sha256:297cf934af64a09b… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"spinnaker","vendor":"spinnaker","versions":[{"status":"affected","version":"< 2025.1.6"},{"status":"affected","version":">= 2025.2.0, < 2025.2.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8e706824218718353401f44d308b6cdd700b90c60425111bb8b7190df4f90b8c · sha256:297cf934af64a09b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"LOW","baseScore":7.9,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8e706824218718353401f44d308b6cdd700b90c60425111bb8b7190df4f90b8c · sha256:297cf934af64a09b… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
3 source assertions{"cweId":"CWE-20","description":"CWE-20: Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8e706824218718353401f44d308b6cdd700b90c60425111bb8b7190df4f90b8c · sha256:297cf934af64a09b… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8e706824218718353401f44d308b6cdd700b90c60425111bb8b7190df4f90b8c · sha256:297cf934af64a09b… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-523","description":"CWE-523: Unprotected Transport of Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8e706824218718353401f44d308b6cdd700b90c60425111bb8b7190df4f90b8c · sha256:297cf934af64a09b… · /containers/cna/problemTypes/1/descriptions/0
Source references
1 source assertion{"name":"https://github.com/spinnaker/spinnaker/security/advisories/GHSA-vrjc-q2fh-6x9h","tags":["x_refsource_CONFIRM"],"url":"https://github.com/spinnaker/spinnaker/security/advisories/GHSA-vrjc-q2fh-6x9h"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8e706824218718353401f44d308b6cdd700b90c60425111bb8b7190df4f90b8c · sha256:297cf934af64a09b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.