Junglewise Threat Intelligence

CVE-2022-39272: GO-2022-1071 - Denial of service in flux controllers in github.com/fluxcd modules

CVE-2022-39272 · Severity: low · CVSS 3.1 · Published 2022-10-28

Technologies: github.com/fluxcd/source-controller (Go), github.com/fluxcd/helm-controller (Go), github.com/fluxcd/flux2 (Go), github.com/fluxcd/kustomize-controller (Go). Vendors: Go.

Executive brief

Denial of service in flux controllers in github.com/fluxcd modules

Affected products

  • Go github.com/fluxcd/source-controller
  • Go github.com/fluxcd/image-automation-controller/api
  • Go github.com/fluxcd/image-reflector-controller
  • Go github.com/fluxcd/notification-controller/api
  • Go github.com/fluxcd/helm-controller
  • Go github.com/fluxcd/helm-controller/api
  • Go github.com/fluxcd/source-controller/api
  • Go github.com/fluxcd/image-reflector-controller/api
  • Go github.com/fluxcd/kustomize-controller/api
  • Go github.com/fluxcd/notification-controller
  • Go github.com/fluxcd/flux2
  • Go github.com/fluxcd/kustomize-controller
  • Go github.com/fluxcd/image-automation-controller

Related threats