Impact
A missing authentication check in Fleet’s Git webhook receiver allows an unauthenticated caller to post webhook requests that alter the spec.pollingInterval field of a GitRepo resource in any namespace. Changing this field modifies the polling behaviour of code deployments, effectively enabling an operator to modify cluster deployment parameters without possessing Kubernetes credentials. The vulnerability is a classic privilege‑escalation scenario caused by Missing Authentication (CWE‑306).
Affected Systems
The vulnerability affects SUSE Rancher Fleet 0.16 before 0.16.2. Versions 0.16.2 and later, as well as any older, non‑Fleet products, are not susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity and the EPSS score is not available, so the exact likelihood of exploitation remains uncertain. The alert is not listed in the CISA KEV catalog. An attacker does not need Kubernetes credentials; any host that can reach the gitjob webhook service can send a forged webhook request to trigger the configuration change. Therefore, if the webhook endpoint is exposed to untrusted networks, the risk of exploitation is significant. Regular patching and network restrictions can mitigate this scenario.
OpenCVE Enrichment