PT-2026-22072 · Bitnami · Bitnami Sealed Secrets

1Seal

·

Publicado

2026-02-26

·

Atualizado

2026-03-25

·

CVE-2026-22728

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bitnami Sealed Secrets (affected versions not specified)
Description Bitnami Sealed Secrets is susceptible to a scope-widening attack during the secret rotation process via the /v1/rotate API endpoint. The rotation handler uses untrusted data from spec.template.metadata.annotations within the input SealedSecret to determine the sealing scope for the rotated output. An attacker can exploit this by injecting the annotation sealedsecrets.bitnami.com/cluster-wide=true into the template metadata of a submitted SealedSecret. This allows the attacker to obtain a rotated, cluster-wide version of the secret, bypassing original scope restrictions and enabling them to unseal the secret in any namespace or under any name, potentially recovering plaintext credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-SEALED-SECRETS-2026-22728
CVE-2026-22728
GHSA-465P-V42X-3FMJ
GO-2026-4565
SUSE-SU-2026:1042-1

Produtos afetados

Bitnami Sealed Secrets