Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.11.0, < 0.11.13CPE match | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* | ||
>= 0.12.0, < 0.12.14CPE match | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* | ||
>= 0.13.0, < 0.13.10CPE match | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* | ||
>= 0.14.0, < 0.14.5CPE match | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* | ||
>= 0.15.0, < 0.15.1CPE match | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.