Executive brief
Fission is an open-source framework for serverless functions on Kubernetes. A vulnerability in the MessageQueueTrigger component allows users with limited permissions to steal sensitive credentials (Secrets) and run unauthorized software with elevated privileges. This could lead to a full compromise of the affected environment and unauthorized access to sensitive customer data.
Technical details
The Fission MessageQueueTrigger (MQT) scaler controller contains two privilege escalation primitives. First, the 'getEnvVarlist' function in 'pkg/mqtrigger/scalermanager.go' materialized Secret values into plaintext environment variables within Deployment pod templates, allowing users without 'secrets/get' RBAC to exfiltrate any Secret in the namespace. Second, the 'util.MergePodSpec' function lacked an allowlist, permitting users to inject arbitrary fields into the connector PodSpec, including container images, commands, and service accounts. An attacker with 'messagequeuetriggers/create' permissions can exploit these to escalate privileges to 'deployments/create' or read sensitive data. The issues are fixed in version 1.24.0 by using 'SecretKeyRef' for environment variables and implementing a strict PodSpec field allowlist.
Affected products
- fission fission <= 1.23.0
Timeline
- 2026-05-26: disclosed
- 2026-06-30: advisory
- 2026-06-30: patched: Fixed in v1.24.0