PT-2022-4594 · Flux · Flux
Pjbgf
·
Published
2022-08-31
·
Updated
2024-08-21
·
CVE-2022-36035
CVSS v3.1
7.7
High
| Vector | AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Flux (affected versions not specified)
Description
The issue is related to the improper handling of user-supplied input in the Flux CLI, which results in a path traversal that can be controlled by the attacker. This allows other applications to replace the Flux deployment information with arbitrary content, which is then deployed into the target Kubernetes cluster. Users sharing the same shell between other applications and the Flux CLI commands could be affected by this issue. In some scenarios, no errors may be presented, which may cause end users not to realize that something is amiss.
Recommendations
As a temporary workaround, consider executing Flux CLI in ephemeral and isolated shell environments to ensure no persistent values exist from previous processes.
Upgrading to the latest version of the CLI is still the recommended mitigation strategy.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flux