CVE-2022-24878

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-24878
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24878.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-24878
Aliases
Published
2022-05-06T01:35:08Z
Modified
2025-11-07T00:26:14.858988Z
Severity
  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H CVSS Calculator
Summary
Improper path handling in Kustomization files allows for denial of service
Details

Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious kustomization.yaml allows an attacker to cause a Denial of Service at the controller level. Workarounds include automated tooling in the user's CI/CD pipeline to validate kustomization.yaml files conform with specific policies. This vulnerability is fixed in kustomize-controller v0.24.0 and included in flux2 v0.29.0. Users are recommended to upgrade.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

Git / github.com/fluxcd/flux2

Affected ranges

Type
GIT
Repo
https://github.com/fluxcd/flux2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.0.1
v0.0.1-alpha.1
v0.0.1-beta.1
v0.0.1-beta.2
v0.0.1-beta.3
v0.0.1-beta.4
v0.0.10
v0.0.11
v0.0.12
v0.0.13
v0.0.14
v0.0.15
v0.0.16
v0.0.17
v0.0.18
v0.0.19
v0.0.2
v0.0.20
v0.0.21
v0.0.22
v0.0.23
v0.0.24
v0.0.25
v0.0.26
v0.0.27
v0.0.28
v0.0.3
v0.0.4
v0.0.5
v0.0.6
v0.0.7
v0.0.8
v0.0.9
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.10.0
v0.11.0
v0.12.0
v0.12.1
v0.12.2
v0.12.3
v0.13.0
v0.13.1
v0.13.2
v0.13.3
v0.13.4
v0.14.0
v0.14.1
v0.14.2
v0.15.0
v0.15.1
v0.15.2
v0.15.3
v0.16.0
v0.16.1
v0.16.2
v0.17.0
v0.17.1
v0.17.2
v0.18.0
v0.18.1
v0.18.2
v0.18.3
v0.19.0
v0.19.1
v0.2.0
v0.2.1
v0.2.2
v0.2.3
v0.2.4
v0.2.5
v0.2.6
v0.20.0
v0.20.1
v0.21.0
v0.21.1
v0.22.0
v0.22.1
v0.23.0
v0.24.0
v0.24.1
v0.25.0
v0.25.1
v0.25.2
v0.25.3
v0.26.0
v0.26.1
v0.26.2
v0.26.3
v0.27.0
v0.27.1
v0.27.2
v0.28.0
v0.28.1
v0.28.2
v0.28.3
v0.28.4
v0.28.5
v0.3.0
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.4
v0.5.5
v0.5.6
v0.5.7
v0.5.8
v0.5.9
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.7.5
v0.7.6
v0.7.7
v0.8.0
v0.8.1
v0.8.2
v0.9.0
v0.9.1

Git / github.com/fluxcd/kustomize-controller

Affected ranges

Type
GIT
Repo
https://github.com/fluxcd/kustomize-controller
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

api/v0.*

api/v0.0.10
api/v0.0.11
api/v0.0.12
api/v0.0.13
api/v0.0.8
api/v0.0.9
api/v0.1.0
api/v0.1.1
api/v0.1.2
api/v0.10.0
api/v0.11.0
api/v0.11.1
api/v0.12.0
api/v0.12.1
api/v0.12.2
api/v0.13.0
api/v0.13.1
api/v0.13.2
api/v0.13.3
api/v0.14.0
api/v0.14.1
api/v0.15.0
api/v0.15.1
api/v0.15.2
api/v0.15.3
api/v0.15.4
api/v0.15.5
api/v0.16.0
api/v0.17.0
api/v0.18.0
api/v0.18.1
api/v0.18.2
api/v0.19.0
api/v0.19.1
api/v0.2.0
api/v0.2.1
api/v0.2.2
api/v0.20.0
api/v0.20.1
api/v0.20.2
api/v0.21.0
api/v0.21.1
api/v0.22.0
api/v0.22.1
api/v0.22.2
api/v0.22.3
api/v0.23.0
api/v0.24.0
api/v0.24.1
api/v0.24.2
api/v0.24.3
api/v0.24.4
api/v0.25.0
api/v0.26.0
api/v0.26.1
api/v0.26.2
api/v0.26.3
api/v0.27.0
api/v0.27.1
api/v0.28.0
api/v0.29.0
api/v0.3.0
api/v0.4.0
api/v0.5.0
api/v0.5.1
api/v0.5.2
api/v0.5.3
api/v0.6.0
api/v0.6.1
api/v0.6.2
api/v0.6.3
api/v0.7.0
api/v0.7.1
api/v0.7.2
api/v0.7.3
api/v0.7.4
api/v0.8.0
api/v0.8.1
api/v0.9.0
api/v0.9.1
api/v0.9.2
api/v0.9.3

v0.*

v0.0.1
v0.0.1-alpha.1
v0.0.1-alpha.2
v0.0.1-alpha.3
v0.0.1-alpha.4
v0.0.1-alpha.5
v0.0.1-alpha.6
v0.0.1-alpha.7
v0.0.1-alpha.8
v0.0.1-alpha.9
v0.0.1-beta.1
v0.0.1-beta.2
v0.0.10
v0.0.11
v0.0.12
v0.0.13
v0.0.2
v0.0.3
v0.0.4
v0.0.5
v0.0.6
v0.0.7
v0.0.8
v0.0.9
v0.1.0
v0.1.1
v0.1.2
v0.10.0
v0.11.0
v0.11.1
v0.12.0
v0.12.1
v0.12.2
v0.13.0
v0.13.1
v0.13.2
v0.13.3
v0.14.0
v0.14.1
v0.15.0
v0.15.1
v0.15.2
v0.15.3
v0.15.4
v0.15.5
v0.16.0
v0.17.0
v0.18.0
v0.18.1
v0.18.2
v0.19.0
v0.19.1
v0.2.0
v0.2.1
v0.2.2
v0.20.0
v0.20.1
v0.20.2
v0.21.0
v0.21.1
v0.22.0
v0.22.1
v0.22.2
v0.22.3
v0.23.0
v0.24.0
v0.24.1
v0.24.2
v0.24.3
v0.24.4
v0.25.0
v0.26.0
v0.26.1
v0.26.2
v0.26.3
v0.27.0
v0.27.1
v0.28.0
v0.3.0
v0.4.0
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.8.0
v0.8.1
v0.9.0
v0.9.1
v0.9.2
v0.9.3