Description


Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.

Related CPE's


a

suse

rancher_fleet

4

Weaknesses



CWE-1287

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

9.9 · Critical

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-07-02T17:16:59.667Z

3 months ago

Last modified

2026-07-06T12:44:21.767Z

3 months ago