Impact
A race condition in flightctl’s configureRepoHTTPSClient function allows a tenant’s per-repository TLS configuration—including InsecureSkipVerify, custom CA bundles, and mTLS client certificates—to be written into a process‑global client.Protocols map. Because flightctl workers render devices for multiple tenants concurrently, the configuration written last wins for all in‑flight git.Clone calls, causing another tenant’s TLS settings to be used. The leak can expose a tenant’s client credentials or allow certificate verification to be bypassed, compromising confidentiality, integrity, and authentication of secure connections. The flaw is a typical race condition (CWE‑413).
Affected Systems
Red Hat Advanced Cluster Management for Kubernetes 2 and Red Hat Edge Manager 1 both deploy the flightctl component that renders device configurations. Version details are not specified, so any release containing flightctl is potentially impacted.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity while an EPSS score of <1 % suggests a low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would require an attacker to influence Repository resource definitions that share the same worker pool—by setting skipServerVerification or supplying client certificates—to trigger the race condition and bleed TLS settings to another tenant. Given these constraints, the risk is moderate but non‑negligible for multi‑tenant clusters, particularly when tenants configure insecure TLS settings.
OpenCVE Enrichment