目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-59341— Sealed Secrets 远程代码执行漏洞

一分钟漏洞结论

影响对象
Bitnami sealed-secrets
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Sealed Secrets 控制器的未认证 POST 端点存在安全漏洞。通过提交包含自定义 Go 模板逻辑在 中的修改后负载,拥有内部网络访问权限的攻击者可以利用该处理程序作为解密预言机(decryption oracle),从而恢复任意密封机密(sealed secret)的完整明文。 和 处理程序会调用 对目标机密进行解密,随后使用解密后的负载作为评估上下文,渲染 中发现的任何 Go 模板(见 )。模板执行过程中遇到的错误会直接反映在返回的 HTTP 响应状态码中。 AEAD 标签绑定缺失: 字段未被纳入 A

CVSS 4.2 · Medium EPSS 0.40% · P32

影响版本矩阵 2

厂商产品 版本范围状态
Bitnami sealed-secrets ≤ 0.38.4 affected
0.40.0 unaffected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-59341 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Sealed Secrets: decryption oracle via Go template injection in unauthenticated controller endpoints
来源: CVE Program / CVE List V5
Vulnerability Description
A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an attacker with internal network access can abuse the handler as a decryption oracle to recover the full plaintext of any sealed secret. The POST /v1/verify and /v1/rotate handlers call Unseal() to decrypt target secrets, then render any Go templates found in spec.template.data.* using the decrypted payload as the evaluation context (pkg/apis/sealedsecrets/v1alpha1/sealedsecret_expansion.go). Errors encountered during template execution are directly reflected in the resulting HTTP response status codes. Missing AEAD label binding: the spec.template.data field is omitted from the AEAD authenticated-data label binding ciphertext to metadata. As a result, an attacker can copy a target's valid metadata and encryptedData verbatim, satisfying AEAD decryption and label validation, while freely replacing spec.template.data with arbitrary template logic. Side-channel oracle: template execution errors map directly to HTTP response codes. HTTP 200 (OK) indicates template execution succeeded; HTTP 409 (Conflict) indicates template execution failed (e.g. via {{ fail "..." }}). By injecting conditional statements such as {{ if eq (substr 0 1 .password) "S" }}ok{{ else }}{{ fail "x" }}{{ end }}, an attacker receives an HTTP 200 status when a character guess is correct and an HTTP 409 when it is incorrect. This differential response leaks one character-equality bit per request, allowing full secret extraction over successive queries. Attack vector & prerequisites: unauthenticated; requires network access to the controller's internal service port (:8080). Although this service is not exposed to the public internet by default, it is accessible to any pod within the Kubernetes cluster or via a kubectl port-forward connection.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Bitnami sealed-secrets 0 ~ 0.38.4 -

二、漏洞 CVE-2026-59341 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-59341 的情报信息

请登录查看更多情报信息。

CVE-2026-59341 厂商安全公告 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-59341

暂无评论


发表评论