CVE-2026-93537 SUSE Rancher Fleet 文件读取漏洞
影响攻击者可越权读取服务器文件并泄露凭据
SUSE Rancher Fleet 在处理 GitRepo 资源引用的仓库内容时存在路径处理缺陷。拥有向该仓库推送内容或创建/修改 GitRepo 权限的用户,可诱使 Fleet 读取其处理环境文件系统中的文件,并将内容写入生成的 Bundle 资源中。
影响范围
Fleet 0.16 < 0.16.2、0.15 < 0.15.7、0.14 < 0.14.11、0.13 < 0.13.16、0.12 < 0.12.20,以及可能更早的不受支持版本。
漏洞详情
该漏洞属于路径遍历/任意文件读取类问题。Fleet 在生成 Bundle 资源时会读取 bundle 内容中引用的文件路径,但未充分限制路径范围,导致可读取处理环境本地文件系统上的任意文件。读取到的内容会被包含进 Bundle 资源,从而被攻击者获取。
利用条件与风险
利用需具备向目标 GitRepo 仓库推送内容或创建/修改 GitRepo 的权限,属于低权限用户越权读取。实战中可导致 Helm 仓库凭据、配置等敏感信息泄露,风险中等。
修复建议
升级至 Fleet 0.16.2、0.15.7、0.14.11、0.13.16 或 0.12.20 及以上版本。临时缓解措施暂无公开信息,建议限制对 GitRepo 资源的创建/修改权限及仓库推送权限。
A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated Bundle resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured.
This affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions.