Impact
Woodpecker is a CI/CD engine that, from version 1.0.0 through 3.16.0, exposes a Kubernetes backend flaw. The backend_options.kubernetes.serviceAccountName field allows pipeline steps to specify any ServiceAccount name, and the pod construction code copies this value directly into the pod spec without checking the requester’s authorization. Consequently, any user with push permission to a repository can trigger pipeline pods that run under an arbitrary ServiceAccount inside the pipeline namespace. If the chosen ServiceAccount possesses elevated RBAC rights, the attacker can read cluster secrets such as database credentials, API keys, and TLS certificates, and may even take full control of the Kubernetes cluster.
Affected Systems
The vulnerability affects the Woodpecker CI product, specifically versions ranging from 1.0.0 up to and including 3.16.0. The issue was addressed and fixed in the 3.16.0 release.
Risk and Exploitability
To date, the CVSS score of 9.0 marks this flaw as critical. The EPSS score of < 1 % indicates a very low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalogue. The likely attack vector is an authorised repository push user; the attacker can trigger pipeline execution that runs under a chosen ServiceAccount, thereby elevating privileges, exfiltrating secrets, or taking over the cluster. The flaw is mitigated by upgrading to version 3.16.0 or later, which removes the unchecked ServiceAccount bridging.
OpenCVE Enrichment
Github GHSA