Impact
The flaw lets an attacker register a cluster with spoofed labels that are blindly applied to the Cluster object used by Fleet. By manipulating labels in the reserved management.cattle.io namespace, the attacker’s cluster can satisfy targeting rules that were intended for another tenant’s cluster, causing unauthorized bundles—including those containing secrets—to be deployed. This abuse of authority is reflected by the CWE‑290 and CWE‑639 weaknesses.
Affected Systems
SUSE Rancher Fleet versions 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and all older releases.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, with no EPSS score available and no listing in CISA KEV. Exploitation requires the ability to register a cluster in a shared workspace; an attacker can then manipulate cluster labels to trigger target resolution intended for other tenants, potentially leading to the deployment of unauthorized bundles and exposure of sensitive information.
OpenCVE Enrichment