PT-2026-99905 · Suse · Rancher Fleet
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SUSE Rancher Fleet versions 0.16 through 0.16.1
Description
The Git webhook receiver (the gitjob webhook service) fails to verify incoming requests when a webhook secret is not configured. This allows a remote caller with network access to the service, even without Kubernetes credentials, to modify the
spec.pollingInterval field of a matching GitRepo resource across any namespace, enabling unauthorized configuration changes.Recommendations
Update SUSE Rancher Fleet to version 0.16.2.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rancher Fleet