SCA: security update for github.com/kcp-dev/kcp (GHSA-w2rr-38wv-8rrp)

critical Tenable Self-Hosted Container Security Plugin ID 421169

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container
workloads. Prior to 0.26.3, the identified vulnerability allows creating or deleting an object via the
APIExport VirtualWorkspace in any arbitrary target workspace for pre-existing resources. By design, this
should only be allowed when the workspace owner decides to give access to an API provider by creating an
APIBinding. With this vulnerability, it is possible for an attacker to create and delete objects even if
none of these requirements are satisfied, i.e. even if there is no APIBinding in that workspace at all or
the workspace owner has created an APIBinding, but rejected a permission claim. A fix for this issue has
been identified and has been published with kcp 0.26.3 and 0.27.0. (CVE-2025-29922)

See Also

https://github.com/advisories/GHSA-w2rr-38wv-8rrp

Plugin Details

Severity: Critical

ID: 421169

Version: Revision 1.17

Type: Local

Family: SCA Checks

Published: 3/21/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.8

Percentile: 97.03

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N

CVSS Score Source: CVE-2025-29922

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/20/2025

Vulnerability Publication Date: 3/20/2025

Reference Information

CVE: CVE-2025-29922

cwe: CWE-285