Impact
The vulnerability is a path traversal flaw in the valuesFiles handling of SUSE Rancher Fleet’s helm deployment, which can be exploited by a user who can supply or modify bundle content. By referencing files that exist outside the intended bundle directory, the attacker can cause Fleet to read arbitrary files from the environment’s filesystem and embed their contents into the generated Bundle resource. The data exposed can include sensitive configuration data or credential material that the attacker otherwise has no permission to read through Kubernetes RBAC, such as Helm registry credentials supplied to the bundle job.
Affected Systems
Affected versions of SUSE Rancher Fleet include 0.16 versions earlier than 0.16.2, 0.15 earlier than 0.15.7, 0.14 earlier than 0.14.11, 0.13 earlier than 0.13.16, 0.12 earlier than 0.12.20, and potentially older unsupported releases.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk, and the attack can be performed when an attacker has push access to the Git repository that feeds bundle content or permission to create or modify a GitRepo resource. Exploitation requires the attacker to supply a specially crafted valuesFiles path that points to an out-of-bundle file; the Fleet bundle-processing job then reads the file from the host filesystem. The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting that widespread exploitation is not yet documented but the threat remains present.
OpenCVE Enrichment