Impact
SUSE Rancher Fleet’s Helm Deployer neglects to validate valuesFrom references, permitting a tenant who can create or modify Helm releases to point to a secret residing in another tenant’s namespace. This flaw unlocks read access to sensitive data—such as API keys and passwords—that belong to a different tenant, constituting a confidentiality breach (CWE‑1287). The impact is limited to unauthorized disclosure of credentials across tenants; no other privilege escalation is indicated in the description.
Affected Systems
The vulnerability is present in Rancher Fleet releases up to, but not including, 0.15.2, 0.14.6, 0.13.11, and 0.12.15. Specifically, the affected ranges are 0.12.0‑0.12.14, 0.13.0‑0.13.10, 0.14.0‑0.14.5, and 0.15.0‑0.15.1. Any cluster running one of these versions and permitting tenants to deploy or edit Helm charts is at risk.
Risk and Exploitability
The CVSS base score of 9.9 signifies critical severity, while an EPSS score of < 1% indicates that widespread exploitation is currently unlikely. The vulnerability is not catalogued in CISA’s KEV list. Exploitation requires only internal cluster access: a tenant with Helm deployment rights can perform the attack, and no external network interaction is necessary. Given the high confidentiality impact and the potential for compromised credentials to be used for further malicious activity, the risk remains substantial.
OpenCVE Enrichment
Github GHSA