Database/Control plane, storage & DevOps
Renovate: unescaped Maven Wrapper distributionType lets a repository run commands in the bot
Impact
This is a second, separate injection point from the Gradle Wrapper one: the Maven Wrapper manager passes an unescaped distributionType value from maven-wrapper.properties into a shell invocation. A repository Renovate updates can therefore execute arbitrary commands in the Renovate container, with whatever Git and registry credentials that process carries. On a fleet where Renovate keeps Kubernetes manifests and container image tags current, that is code execution in the path that decides what runs on the GPU nodes. Affects deployments running with binarySource=docker.
Who can reach it
Anyone able to commit a crafted maven-wrapper.properties to a repository the self-hosted Renovate instance processes. No authentication against the Renovate host is required.
What to do
Upgrade to Renovate 44.14.7 and restart the bot or roll its deployment; the advisory does not name a separate mitigation for this path beyond restricting unsafe executions. Patch is a service-level change only, no node maintenance. Rotate credentials held by the Renovate user if exploitation cannot be excluded.
References
Related entries
- Ceph RGW (STS session tokens): Any tenant holding one ordinary STS session token can edit it into RGW superuser. RGWNCVD-2026-040-ceph-rgw-sts-session-tokens · Ceph RGW (STS session tokens)High
- CloudNativePG (role password handling, pg_stat_statements exposure): CREDENTIAL DISCLOSURE ACROSS THE TENANT BOUNDARYNCVD-2026-049-cloudnativepg-role-password-hand · CloudNativePG (role password handling, pg_stat_statements exposure)High
- IBM Spectrum Scale Container Native Storage Access: A local user obtains root privileges through the Spectrum ScaleCVE-2022-41736 · IBM Spectrum Scale Container Native Storage AccessHigh
- ConnectWise ScreenConnect: Path traversal enabling remote code executionCVE-2024-1708 · ConnectWise ScreenConnectHigh
- AMD Graphics Driver - crafted pointer leading to arbitrary writes: A specially crafted pointer passed to the AMDCVE-2024-36352 · AMD Graphics Driver - crafted pointer leading to arbitrary writesHigh
- Dell CloudLink (command injection): Command injection giving a privileged user full control of the CloudLink systemCVE-2025-30479 · Dell CloudLink (command injection)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.