PT-2026-99904 · Suse · Rancher Fleet
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SUSE Rancher Fleet versions prior to 0.16.1
SUSE Rancher Fleet versions prior to 0.15.6
SUSE Rancher Fleet versions prior to 0.14.10
SUSE Rancher Fleet versions prior to 0.13.15
SUSE Rancher Fleet versions prior to 0.12.19
Description
A cross-tenant authorization issue exists during agent-initiated cluster registration. Cluster labels provided by the registering agent, including those in the reserved
management.cattle.io/ namespace (such as the cluster display name label), are applied to the resulting upstream Cluster object. Since Fleet uses these labels to resolve GitRepo and Bundle targets, a user registering a cluster into a shared Fleet workspace namespace could manipulate labels to satisfy targeting rules intended for a different cluster.Recommendations
Update to version 0.16.1 or newer.
Update to version 0.15.6 or newer.
Update to version 0.14.10 or newer.
Update to version 0.13.15 or newer.
Update to version 0.12.19 or newer.
Exploit
Fix
Authentication Bypass by Spoofing
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rancher Fleet