Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `ResolutionRequests` (e.g. by creating `TaskRuns` or `PipelineRuns` that use the git resolver) can read arbitrary files from the resolver pod's filesystem, including ServiceAccount tokens. The file contents are returned base64-encoded in `resolutionrequest.status.data`. Versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2 contain a patch.
The vulnerability (CWE-22) consists of insufficient validation of the path provided in the `pathInRepo` parameter when handling requests by the git resolver. A tenant with permissions to create `ResolutionRequests` objects — for example by creating `TaskRuns` or `PipelineRuns` using the git resolver — can provide a crafted path containing path traversal sequences (e.g., `../`). As a result, the resolver reads a file outside the intended repository directory, and its contents are returned encoded in base64 format in the `resolutionrequest.status.data` field, accessible to the user.
An attacker can read arbitrary files from the resolver pod's file system, including Kubernetes ServiceAccount tokens, which may enable privilege escalation and takeover of cluster resources.
Update Tekton Pipelines to one of the patched versions: 1.0.1, 1.3.3, 1.6.1, 1.9.2, or 1.10.2. Patches are available in the project repository on GitHub (tektoncd/pipeline). As a temporary measure, consider restricting permissions to create `ResolutionRequests`, `TaskRuns`, and `PipelineRuns` objects only to trusted users.
Tekton Pipelines in versions from 1.0.0 (inclusive) to versions: 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2 (exclusive) — that is, all versions in the 1.0.x, 1.3.x, 1.6.x, 1.9.x, and 1.10.x branches before the release of the respective patches.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NLinuxfoundation Tekton Pipelines
APPLinuxfoundation1.0.01.1.0 – 1.3.3 (excl.)1.4.0 – 1.6.1 (excl.)1.7.0 – 1.9.2 (excl.)1.10.0 – 1.10.2 (excl.)
Related vulnerabilities
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version...
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version...
Projekt Tekton Pipelines udostępnia zasoby w stylu k8s do deklarowania pipelinów CI/CD. Przed wersją 1.11.1 ob...
Projekt Tekton Pipelines zapewnia zasoby o stylistyce k8s do deklarowania pipelineów CI/CD. Przed wersją 1.11....
Projekt Tekton Pipelines udostępnia zasoby w stylu k8s do deklarowania pipelinów CI/CD. W wersjach od 0.43.0 d...