Database/Control plane, storage & DevOps
Harness: missing space-scoped access control lets any authenticated user read other spaces' infra provider configs
Impact
Harness through 3.3.0 does not check space membership on the infrastructure provider read/list endpoints, so any logged-in user can pass an arbitrary space identifier and pull back that space's provider configuration. The exposed metadata includes Docker endpoints, TLS certificate paths and cloud project identifiers - a map of the build and delegate infrastructure behind another team's pipelines. On a shared GPU fleet where Harness drives image builds and job submission, this hands a low-privileged tenant the addresses and cert locations needed to plan a follow-on attack against a neighbour's build plane. Confidentiality only; no write or execution is claimed.
Who can reach it
Any authenticated Harness user, over the network, with a valid login but no membership in the target space. No admin role required.
What to do
Upgrade Harness past 3.3.0 to a release carrying the access-control fix and restart the Harness service; the advisory does not name a fixed version, so confirm against the vendor issue before scheduling. Until then, review who holds accounts on the instance and rotate any credentials or certificates whose paths were exposed. Control-plane only - no GPU node needs to be drained.
References
Related entries
- Flux CD (allow-webhooks NetworkPolicy, notification-controller event server): CROSS-TENANT EVENT FORGERY: theNCVD-2026-057-flux-cd-allow-webhooks-networkpo · Flux CD (allow-webhooks NetworkPolicy, notification-controller event server)High
- OpenSSH through 10.0 - mm_answer_authpassword uses an integer 'authenticated' flag that does not resist a single bitCVE-2023-51767 · OpenSSH through 10.0 - mm_answer_authpassword uses an integer 'authenticated' flag that does not resist a single bit…High
- AMD Radeon RGB tool - signature verification on files in the installation directory: The Radeon RGB tool doesCVE-2024-36334 · AMD Radeon RGB tool - signature verification on files in the installation directoryHigh
- Intel Neural Compressor (SQL injection, second instance): A second SQL-injection path in Neural Compressor reachableCVE-2024-39766 · Intel Neural Compressor (SQL injection, second instance)High
- Redis: Authenticated user triggers a stack/heap out-of-bounds write in hyperloglog opsCVE-2025-32023 · RedisHigh
- Sidero Omni: SAML assertion replay race lets a captured saml-session token be redeemed more than onceCVE-2026-45720 · Sidero Omni (SAML session interceptor, internal/pkg/auth/interceptor/saml.go)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.