A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. An attacker with git push access to a Fleet-monitored repository could overwrite Pod Security Standards (PSS) enforcement labels on a target namespace. This allows the attacker to weaken admission controls and deploy workloads that PSS policies would otherwise block.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.12.0, < 0.12.15CPE match | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* | ||
>= 0.13.0, < 0.13.11CPE match | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* | ||
>= 0.14.0, < 0.14.6CPE match | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* | ||
>= 0.15.0, < 0.15.2CPE match | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.