Impact
The Sealed Secrets controller exposes an unprotected POST endpoint that decrypts sealed secrets and then processes Go templates embedded in the decrypted payload, a flaw classified as CWE‑203. By submitting a crafted template expression within spec.template.data, an internal attacker can cause the service to return HTTP 200 when a template fragment evaluates successfully and HTTP 409 when it fails. The attacker can exploit this differential response as a decryption oracle to learn one character of the secret and eventually recover the entire plaintext. This vulnerability permits leakage of confidential secret data without authentication but with internal network access, and it does not elevate privileges or allow arbitrary code execution beyond secret disclosure.
Affected Systems
The flaw resides in the Bitnami Sealed Secrets controller, specifically the POST /v1/verify and /v1/rotate handlers. Any pod within the same Kubernetes cluster or an entity connected via kubectl port‑forward can reach the controller’s internal service port 8080. No specific product versions are to the fix later described by Bitnami.
Risk and Exploitability
The CVSS score of 4.2 indicates low overall severity, and the EPSS score is below 1 %, meaning exploitation is not common. The vulnerability is not listed in the CISA KEV catalog. However, because the attack requires only internal network access and exposes the controller service to many pods it is significant. Attackers can recover secrets with limited reconnaissance, making this a concern for environments where secrets are highly sensitive.
OpenCVE Enrichment