在 SUSE Rancher Fleet 中发现了一个跨租户授权问题。在由代理(Agent)发起的集群注册过程中,注册代理所提供的集群标签(包括属于保留命名空间 的标签,例如集群显示名称标签)会被应用到最终生成的上游 Cluster 对象中。由于 Fleet 会基于这些集群标签来解析 GitRepo 和 Bundle 的目标集群,因此,能够向其他租户共享的 Fleet 工作区命名空间中注册集群的一方,可以使其自身的集群满足管理员本意为其他集群设定的目标匹配规则,从而导致未授权的资源部署或数据访问。 该漏洞影响 SU
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78424 | 8.8 HIGH | OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution o |
| CVE-2026-93540 | 6.5 MEDIUM | Fleet applies namespace labels and annotations without the bundle's service account privil |
| CVE-2026-93537 | 6.5 MEDIUM | Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle dir |
| CVE-2026-93539 | 5.4 MEDIUM | Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver |
No comments yet