CVE-2022-24878
Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller v
Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious kustomization.yaml allows an attacker to cause a Denial of Service at the controller level. Workarounds include automated tooling in the user's CI/CD pipeline to validate kustomization.yaml files conform with specific policies.
This vulnerability is fixed in kustomize-controller v0.24.0 and included in flux2 v0.29.0. Users are recommended to upgrade.
HIGH · CVSS 7.7
EPSS 0.0031
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0