HIGH
Rancher Fleet Helm Values are stored inside BundleDeployment in plain text
Published Sep 2, 2025
7.7
HIGHCVSS 3.1
EPSS 0.23%
Description
Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets.
Affected products
-
Affected
- ≥ 0.11.0, < 0.11.10
- ≥ 0.12.0, < 0.12.6
- ≥ 0.13.0, < 0.13.1-0.20250806151509-088bcbea7edb
No data.
No data.
No Red Hat product state for this CVE.
github.com/rancher/fleet
Go
Introduced 0.13.0 Fixed 0.13.1-0.20250806151509-088bcbea7edbgithub.com/rancher/fleet
Go
Introduced 0.12.0 Fixed 0.12.6github.com/rancher/fleet
Go
Introduced 0.11.0 Fixed 0.11.10
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/rancher/fleet | 0.13.0 | 0.13.1-0.20250806151509-088bcbea7edb |
| Go | github.com/rancher/fleet | 0.12.0 | 0.12.6 |
| Go | github.com/rancher/fleet | 0.11.0 | 0.11.10 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-52284
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-54941 Advisory
- https://github.com/advisories/GHSA-6h9x-9j5v-7w9h Advisory
- https://github.com/rancher/fleet/commit/088bcbea7edb844d7e6fc3649d9954f763cf68a9
- https://github.com/rancher/fleet/security/advisories/GHSA-6h9x-9j5v-7w9h
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner suse
Published Sep 2, 2025
Updated Sep 2, 2025
Reserved Nov 6, 2024
Link CVE-2024-52284
CISA Vulnrichment
Updated Sep 2, 2025
Red Hat
No data
GitHub
Link GHSA-6H9X-9J5V-7W9H