Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.
References
| Link | Resource |
|---|---|
| https://github.com/rancher/fleet/security/advisories/GHSA-xr65-5cpm-g36x | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-02 17:16
Updated : 2026-07-06 12:44
NVD link : CVE-2026-44935
Mitre link : CVE-2026-44935
CVE.ORG link : CVE-2026-44935
JSON object : View
Products Affected
suse
- rancher_fleet
CWE
CWE-1287
Improper Validation of Specified Type of Input
