Database/Control plane, storage & DevOps
FlyteAdmin (built-in OAuth authorization server, default client secret hashes): Turning on Flyte's built-in
Impact
Turning on Flyte's built-in authorization server without replacing the shipped default client ID hashes leaves publicly known credentials in place. Anyone who reads the docs authenticates as FlytePropeller and reaches the FlyteAdmin control plane, which means enumerating and manipulating every tenant's workflow executions on a deployment the operator believes is authenticated.
Who can reach it
Any internet or network host that can reach FlyteAdmin, using the documented default client secrets. No prior access needed.
What to do
Rotate the client ID hashes to values you generated, then upgrade FlyteAdmin to 1.1.44 or later and restart. Verify the running config does not still carry the shipped defaults after the upgrade - this is a configuration flaw that a version bump alone will not correct.
References
Related entries
- IBM Storage Scale Container Native Storage Access (network namespace exposure): Hosts outside the cluster can openCVE-2022-41738 · IBM Storage Scale Container Native Storage Access (network namespace exposure)High
- Schneider Electric APC NetBotz 4 environmental appliances (355/450/455/550/570, V4.7.0 and prior): No rate limitingCVE-2022-43377 · Schneider Electric APC NetBotz 4 environmental appliances (355/450/455/550/570, V4.7.0 and prior)High
- Linux nfsd (NFS server): NFSD buffer overflow - a client can force the send buffer to overflow the page arrayCVE-2022-43945 · Linux nfsd (NFS server)High
- GlusterFS (dht translator, dht_setxattr_mds_cbk): A use-after-free in the distributed-hash translator crashes the brickCVE-2022-48340 · GlusterFS (dht translator, dht_setxattr_mds_cbk)High
- AMD SMM communications buffer - TOCTOU (AMD-SB-3003): A time-of-check-to-time-of-use race on the SMM communicationsCVE-2023-20578 · AMD SMM communications buffer - TOCTOU (AMD-SB-3003)High
- NetApp ONTAP 9 HTTP service: An unauthenticated attacker crashes the ONTAP HTTP service, taking down the management andCVE-2023-27314 · NetApp ONTAP 9 HTTP serviceHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.