Impact
The source-controller includes a path traversal flaw (CWE-23) that allows an attacker who can influence a bucket referenced by a Bucket resource to cause the controller to write fetched object data to file paths outside its per‑reconciliation working directory. While the controller performs digest verification of stored artifacts and downstream Flux controllers reject mismatched digests, they do not prevent the source-controller pod from writing files wherever it has filesystem permissions. A separate surface exists for users who can create or update GitRepository resources; they can cause the controller to test for the existence of paths outside the cloned repository and the result is exposed via the resource’s status, allowing limited enumeration of file paths on the controller pod. These capabilities provide an attacker with the ability to write arbitrary files within the controller pod’s filesystem and to discover existing files, which could facilitate further compromise or covert persistence.
Affected Systems
Flux CD source-controller v0.0.17 through v1.8.4 is affected, including the v1.6.0 and later releases that introduced sparse‑checkout support for GitRepository resources. The flaw is present only in these versions and has been fixed in source‑controller v1.8.5.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating moderate severity. EPSS data is unavailable and the issue is not listed in CISA’s KEV catalog, so the current likelihood of exploitation is unknown. An attacker with the ability to influence the contents of a referenced bucket or to create/update GitRepository resources can exploit the flaw; the attack vector is most likely within the Kubernetes cluster where the source-controller pod runs. Even without exploiting the digests, the ability to write arbitrary files to the pod’s filesystem is a significant risk, especially if the pod runs privileged or has access to sensitive volume mounts. Enumeration of file paths could aid future attacks or reveal additional sensitive data.
OpenCVE Enrichment
Github GHSA