Vulnerability Description
Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or `.spec.timeout` (and structured variations of these fields), causing the entire object type to stop being processed. This issue is patched in version 0.35.0. As a workaround, Admission controllers can be employed to restrict the values that can be used for fields `.spec.interval` and `.spec.timeout`, however upgrading to the latest versions is still the recommended mitigation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fluxcd | Flux2 | >= 0.1.0, < 0.35.0 |
| Fluxcd | Helm-Controller | >= 0.0.2, < 0.24.0 |
| Fluxcd | Image-Automation-Controller | >= 0.1.0, < 0.26.0 |
| Fluxcd | Image-Reflector-Controller | >= 0.1.0, < 0.22.0 |
| Fluxcd | Kustomize-Controller | >= 0.0.2, < 0.29.0 |
| Fluxcd | Notification-Controller | >= 0.0.2, < 0.27.0 |
| Fluxcd | Source-Controller | >= 0.0.2, < 0.30.0 |
Related Weaknesses (CWE)
References
- https://github.com/fluxcd/flux2/security/advisories/GHSA-f4p5-x4vc-mh4vThird Party Advisory
- https://github.com/kubernetes/apimachinery/issues/131Issue TrackingPatchThird Party Advisory
- https://github.com/fluxcd/flux2/security/advisories/GHSA-f4p5-x4vc-mh4vThird Party Advisory
- https://github.com/kubernetes/apimachinery/issues/131Issue TrackingPatchThird Party Advisory
FAQ
What is CVE-2022-39272?
CVE-2022-39272 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either th...
How severe is CVE-2022-39272?
CVE-2022-39272 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-39272?
Check the references section above for vendor advisories and patch information. Affected products include: Fluxcd Flux2, Fluxcd Helm-Controller, Fluxcd Image-Automation-Controller, Fluxcd Image-Reflector-Controller, Fluxcd Kustomize-Controller.