Description
Missing filtering when the helmRepoURLRegex field isn-t set on a GitRepo resource in SUSE Rancher Fleet-s bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (BasicAuth) to any URL specified in the helm.repo field of a fleet.yaml file, allowing attackers able to push to fleet monitored git repos to leak helm access credentials.
CVSS 5EPSS 0.33%Risque 0.51
Voir la source- Publication
- 2026-07-06 11:16:27
- Versions concernées
- cannotmatch
- Type
- Logiciel critique
- Vecteur
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N