Junglewise Threat Intelligence

CVE-2022-24817: Improper kubeconfig validation allows arbitrary code execution

CVE-2022-24817 · Severity: low · CVSS 3.1 · Published 2022-05-16

Technologies: github.com/fluxcd/helm-controller (Go), github.com/fluxcd/flux2 (Go), github.com/fluxcd/kustomize-controller (Go). Vendors: Go.

Executive brief

Improper kubeconfig validation allows arbitrary code execution

Affected products

  • Go github.com/fluxcd/helm-controller
  • Go github.com/fluxcd/flux2
  • Go github.com/fluxcd/kustomize-controller

Related threats