Impact
The vulnerability allows a user who can supply bundle content to a GitRepo resource to cause the Fleet controller to perform DNS lookups via the Sprig getHostByName function. The lookup exposes cluster metadata and the list of hosts reachable from the controller, yet it does not affect integrity or availability of the managed clusters.
Affected Systems
The flaw was present in fleet controller versions 0.12.0 through 0.12.18, 0.13.0 through 0.13.14, 0.14.0 through 0.14.9, 0.15.0 through 0.15.5, and 0.16.0. The affected product is SUSE Fleet. Upgrading to 0.12.19, 0.13.15, 0.14.10, 0.15.6, or 0.16.1 removes the flaw.
Risk and Exploitability
With a CVSS base score of 5.3 the vulnerability is moderate. EPSS is not available and the flaw is not listed in the CISA KEV catalog. An attacker must have permission to add or modify bundle content for a GitRepo resource, a privilege generally given to cluster administrators or CI/CD pipelines, to trigger the exploit. The attack vector involves the Fleet controller performing external DNS queries, which can be effective even when outbound traffic is otherwise restricted, so the risk exists in tightly‑controlled environments. The lack of integrity or availability impact does not lower the threat level, as the exposed metadata can aid discovery or lateral movement.
OpenCVE Enrichment