Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsule v0.10.3 and earlier allows authenticated tenant users to inject arbitrary labels into system namespaces (kube-system, default, capsule-system), bypassing multi-tenant isolation and potentially accessing cross-tenant resources through TenantResource selectors. This vulnerability enables privilege escalation and violates the fundamental security boundaries that Capsule is designed to enforce. This vulnerability is fixed in 0.10.4.
Metrics
Affected Vendors & Products
References
History
Mon, 18 Aug 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Projectcapsule
Projectcapsule capsule |
|
Vendors & Products |
Projectcapsule
Projectcapsule capsule |
Mon, 18 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 18 Aug 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsule v0.10.3 and earlier allows authenticated tenant users to inject arbitrary labels into system namespaces (kube-system, default, capsule-system), bypassing multi-tenant isolation and potentially accessing cross-tenant resources through TenantResource selectors. This vulnerability enables privilege escalation and violates the fundamental security boundaries that Capsule is designed to enforce. This vulnerability is fixed in 0.10.4. | |
Title | Capsule tenant owners with "patch namespace" permission can hijack system namespaces label | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-18T16:28:51.317Z
Updated: 2025-08-18T17:39:07.476Z
Reserved: 2025-08-08T21:55:07.966Z
Link: CVE-2025-55205

Updated: 2025-08-18T17:39:02.682Z

Status : Awaiting Analysis
Published: 2025-08-18T17:15:30.117
Modified: 2025-08-18T20:16:28.750
Link: CVE-2025-55205

No data.