Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.
The 'valuesFrom' mechanism in Helm Deployer allows pointing to external sources of configuration values. Due to insufficient validation of these references, a person authenticated as the owner of one tenant can construct a reference pointing to resources (Fleet credentials) belonging to another tenant. The vulnerability thus enables circumventing tenant isolation boundaries without requiring administrative privileges to the system.
An attacker who is an authenticated user of one tenant can gain unauthorized access to Fleet credentials of other tenants, leading to violations of confidentiality, integrity, and availability of resources in a multi-tenant environment.
Update SUSE Rancher Fleet to version: 0.12.15 or later (0.12 branch), 0.13.11 or later (0.13 branch), 0.14.6 or later (0.14 branch), 0.15.2 or later (0.15 branch). Details available in the official vendor security advisory: https://github.com/rancher/fleet/security/advisories/GHSA-xr65-5cpm-g36x
SUSE Rancher Fleet in versions: 0.12 before 0.12.15, 0.13 before 0.13.11, 0.14 before 0.14.6, and 0.15 before 0.15.2.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HSUSE Rancher Fleet
APPSuse0.12.0 – 0.12.15 (excl.)0.13.0 – 0.13.11 (excl.)0.14.0 – 0.14.6 (excl.)0.15.0 – 0.15.2 (excl.)
Related vulnerabilities
SSRF/fałszowanie żądań webhook w SUSE Rancher Fleet — DoS i downgrade
Brak filtrowania, gdy pole helmRepoURLRegex nie jest ustawione w zasobie GitRepo w czytelniku bundli SUSE Ranc...
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
RCE w Adobe Flash Player 21.0.0.242 i wcześniejszych — aktywnie exploitowany
Adobe Flash Player — RCE umożliwiający wykonanie dowolnego kodu