Description
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- SUSE / Rancher0.15.0 – 0.15.1
- SUSE / Rancher0.14.0 – 0.14.5
- SUSE / Rancher0.13.0 – 0.13.10
- SUSE / Rancher0.12.0 – 0.12.14
- SUSE / Rancher0.11.0 – 0.11.13