能够向 GitRepo 资源所引用的代码仓库提供 bundle 内容的用户(例如通过 Git push 访问权限,或通过创建或修改 GitRepo 的权限),可以诱导 SUSE Rancher Fleet 读取处理该 bundle 的环境的文件系统中的文件,并将其内容包含在生成的 Bundle 资源中。此行为可能暴露用户无权通过 Kubernetes RBAC 权限读取的配置信息或凭据材料,其中包括在配置基于路径的 Helm 凭据时提供给 bundle 处理任务的 Helm 注册表凭据。 此漏洞影响以下版本的 Fl
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78424 | 8.8 HIGH | OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution o |
| CVE-2026-93538 | 7.1 HIGH | Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agen |
| CVE-2026-93540 | 6.5 MEDIUM | Fleet applies namespace labels and annotations without the bundle's service account privil |
| CVE-2026-93539 | 5.4 MEDIUM | Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver |
No comments yet