Skip to content

Security Vulnerability Report: CVE-2025-15467 in alpine/k8s:1.32.11 #91

@ByJacob

Description

@ByJacob

Security Vulnerability Report: CVE-2025-15467 in alpine/k8s:1.32.11

Description

A CRITICAL severity vulnerability has been identified in the Docker image alpine/k8s:1.32.11. The affected package is libcrypto3, which is part of the OpenSSL library.

Vulnerability Details

  • CVE ID: CVE-2025-15467
  • Severity: CRITICAL
  • Affected Package: libcrypto3
  • Installed Version: 3.5.4-r0
  • Fixed Version: 3.5.5-r0
  • Docker Image: alpine/k8s:1.32.11

Impact

This vulnerability affects the OpenSSL cryptographic library, which is a critical component for secure communications and encryption operations. Given the CRITICAL severity rating, this vulnerability could potentially:

  • Compromise encrypted communications
  • Allow unauthorized access to sensitive data
  • Enable remote code execution (depending on the specific vulnerability details)

Recommended Action

Immediate action is required to mitigate this vulnerability:

  1. Update the base image to a version that includes libcrypto3 version 3.5.5-r0 or later
  2. Rebuild and redeploy all containers using the affected image
  3. Scan your container registry for other images that may be affected

References

OpenSSL Commits Addressing This Issue

Priority

HIGH PRIORITY - This issue should be addressed immediately due to its CRITICAL severity rating.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions