Database/Container, Kubernetes & orchestration
Rancher Fleet: unauthenticated webhook requests can change GitRepo polling interval in any namespace
Impact
When no webhook secret is configured, Fleet's gitjob webhook receiver accepts incoming requests without verification, and handling one can rewrite spec.pollingInterval on a matching GitRepo in any namespace. A caller with nothing but network reach to the webhook service - no Kubernetes credentials at all - can therefore alter GitOps configuration outside any namespace they are authorized for. The direct effect is limited to how often Fleet reconciles, but on a GPU fleet that governs how fast a corrected manifest, a pinned driver version or a rolled-back GPU Operator chart actually lands; stretching the interval quietly delays remediation across clusters. This is a distinct flaw from CVE-2026-93537 and affects only the 0.16 branch.
Who can reach it
Anyone with network access to the gitjob webhook service in a deployment that has no webhook secret configured. No Kubernetes credentials and no authentication needed.
What to do
Upgrade Fleet to 0.16.2 - older branches are not affected - which means rolling the gitjob deployment, a controller restart with no node drain. Configure a webhook secret so incoming requests are verified, and keep the webhook service off any network broader than the systems that legitimately post to it. Check pollingInterval values on your GitRepo resources for unexpected changes.
References
Related entries
- Docker / moby: Default OCI spec does not mask /proc/acpi, so a container can change host hardware stateCVE-2018-10892 · Docker / mobyMedium
- Harbor: Catalog registry API exposed on an unauthenticated pathCVE-2020-29662 · HarborMedium
- Kubernetes (kube-apiserver): Successful API requests can DoS the apiserverCVE-2020-8552 · Kubernetes (kube-apiserver)Medium
- CRI-O: Containers started with non-empty default inheritable capabilitiesCVE-2022-27652 · CRI-OMedium
- Docker / moby: Supplementary groups not set up properlyCVE-2022-36109 · Docker / mobyMedium
- Buildah: Symlink following when reading .containerignore/.dockerignore discloses host filesCVE-2022-4122 · BuildahMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.