在 Fleet 的 Git Webhook 接收器(即 gitjob Webhook 服务)中发现了一个漏洞。当未配置 Webhook 密钥时,传入的 Webhook 请求未经任何验证即被接受。处理此类请求可能会导致匹配到的 GitRepo 资源中的 spec.pollingInterval 字段发生更改,且该影响可波及任意命名空间(namespace)中的资源。因此,任何拥有对 Webhook 服务网络访问权限但无 Kubernetes 凭据的调用者,都可以修改其未被授权访问的命名空间之外的 GitRepo 配置
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78424 | 8.8 HIGH | OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution o |
| CVE-2026-93538 | 7.1 HIGH | Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agen |
| CVE-2026-93540 | 6.5 MEDIUM | Fleet applies namespace labels and annotations without the bundle's service account privil |
| CVE-2026-93537 | 6.5 MEDIUM | Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle dir |
No comments yet