Description
Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:NExploitability: 3.1 | Impact: 4.0Attack Vector: Network
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Changed
Confidentiality: High
Integrity: None
Availability: None
Affected Packages2 packages
▶CVEListV5suse/rancher0.13.0 — 0.13.1-0.20250806151509-088bcbea7edb+2 🔴Vulnerability Details
5OSVRancher Fleet Helm Values are stored inside BundleDeployment in plain text in github.com/rancher/fleet↗2025-09-08 ▶ CVEListRancher Fleet Helm Values are stored inside BundleDeployment in plain text↗2025-09-02 ▶ OSVCVE-2024-52284: Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values contai↗2025-09-02 ▶ GHSARancher Fleet Helm Values are stored inside BundleDeployment in plain text↗2025-08-29 ▶ OSVRancher Fleet Helm Values are stored inside BundleDeployment in plain text↗2025-08-29 ▶