Suse

Rancher Fleet

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 28.09.2026 15:36:13
  • Zuletzt bearbeitet 07.10.2026 17:00:32

A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environme...

  • EPSS 0.17%
  • Veröffentlicht 28.09.2026 14:45:42
  • Zuletzt bearbeitet 07.10.2026 17:03:05

A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the re...

  • EPSS 0.23%
  • Veröffentlicht 28.09.2026 14:19:55
  • Zuletzt bearbeitet 07.10.2026 17:08:05

A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInt...

  • EPSS 0.17%
  • Veröffentlicht 28.09.2026 14:10:21
  • Zuletzt bearbeitet 07.10.2026 17:13:37

A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the clust...

  • EPSS 0.3%
  • Veröffentlicht 28.09.2026 13:29:10
  • Zuletzt bearbeitet 07.10.2026 17:19:57

A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the env...

  • EPSS 0.22%
  • Veröffentlicht 03.09.2026 15:15:25
  • Zuletzt bearbeitet 07.10.2026 15:08:40

A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository refere...

  • EPSS 0.38%
  • Veröffentlicht 06.07.2026 09:52:18
  • Zuletzt bearbeitet 09.07.2026 20:24:49

Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a do...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 06.07.2026 09:30:20
  • Zuletzt bearbeitet 09.07.2026 20:34:30

Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (B...

  • EPSS 0.41%
  • Veröffentlicht 02.07.2026 16:00:06
  • Zuletzt bearbeitet 06.07.2026 12:44:21

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenant...