
Find real vulnerabilities before they ship
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.
Base Score
9.9| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/rancher/fleet(Go) | 0.15.0 | 0.15.1 | N/A |
| github.com/rancher/fleet(Go) | 0.14.0 | 0.14.5 | N/A |
| github.com/rancher/fleet(Go) | 0.13.0 | 0.13.10 | N/A |
| github.com/rancher/fleet(Go) | 0.12.0 | 0.12.14 | N/A |
| github.com/rancher/fleet(Go) | 0.11.0 | 0.11.13 | N/A |
| Base Score | 9.9 |
|---|---|
| Vector String | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Base Severity | Critical |
| Version | 3.1 |
| Attack Vector (AV) | NETWORK |