Impact
Flyte versions 2.0.1 through 2.0.51 contain a cleartext secret storage vulnerability that allows any user with read access to a Pod to obtain secret values. The embedded secret manager webhook writes base64‑encoded, file‑mounted secret values into the SECRETS environment variable of an init container. Attendees can then read the Pod specification, decode the environment variable, and recover the original secret, thereby compromising confidentiality of sensitive data.
Affected Systems
The affected product is Flyte, developed by flyteorg. All releases from 2.0.1 up to and including 2.0.51 are vulnerable. Users of these versions should verify their current deployment version and apply an upgrade if they are running an affected release.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating a high severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Exploitation requires that an attacker or user possesses Pod read permissions, a privilege that may be granted in many Multi‑Tenant or RBAC‑managed Kubernetes environments. Once an attacker can read the Pod description, they can immediately decode the SECRETS environment variable and expose all stored secrets. The attack vector is therefore largely dependent on the attacker’s level of internal access and the configuration of RBAC policies.
OpenCVE Enrichment