CVE-2022-39272

Name
CVE-2022-39272
Description
Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or `.spec.timeout` (and structured variations of these fields), causing the entire object type to stop being processed. This issue is patched in version 0.35.0. As a workaround, Admission controllers can be employed to restrict the values that can be used for fields `.spec.interval` and `.spec.timeout`, however upgrading to the latest versions is still the recommended mitigation.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://github.com/fluxcd/flux2/security/advisories/GHSA-f4p5-x4vc-mh4v
MISC https://github.com/kubernetes/apimachinery/issues/131

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:fluxcd:source-controller:*:*:*:*:*:*:*:* source-controller >= 0.0.2 < 0.30.0
cpe:2.3:a:fluxcd:source-controller:0.0.1:alpha2:*:*:*:*:*:* source-controller == None == 0.0.1
cpe:2.3:a:fluxcd:notification-controller:0.0.1:alpha2:*:*:*:*:*:* notification-controller == None == 0.0.1
cpe:2.3:a:fluxcd:notification-controller:*:*:*:*:*:*:*:* notification-controller >= 0.0.2 < 0.27.0
cpe:2.3:a:fluxcd:kustomize-controller:*:*:*:*:*:*:*:* kustomize-controller >= 0.0.2 < 0.29.0
cpe:2.3:a:fluxcd:kustomize-controller:0.0.1:alpha1:*:*:*:*:*:* kustomize-controller == None == 0.0.1
cpe:2.3:a:fluxcd:image-reflector-controller:*:*:*:*:*:*:*:* image-reflector-controller >= 0.1.0 < 0.22.0
cpe:2.3:a:fluxcd:image-automation-controller:*:*:*:*:*:*:*:* image-automation-controller >= 0.1.0 < 0.26.0
cpe:2.3:a:fluxcd:helm-controller:*:*:*:*:*:*:*:* helm-controller >= 0.0.2 < 0.24.0
cpe:2.3:a:fluxcd:helm-controller:0.0.1:alpha1:*:*:*:*:*:* helm-controller == None == 0.0.1
cpe:2.3:a:fluxcd:flux2:*:*:*:*:*:*:*:* flux2 >= 0.1.0 < 0.35.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
flux edge-community 0.36.0-r0 None fixed
flux 3.22-community 0.36.0-r0 None fixed
flux 3.21-community 0.36.0-r0 None fixed