CVE-2026-93539 Fleet Git webhook 未验证请求漏洞
影响未授权网络攻击者可篡改任意命名空间下 GitRepo 的轮询配置
CVE-2026-93539 是 SUSE Rancher Fleet 的 Git webhook 接收器(gitjob webhook 服务)中的一处访问控制缺陷。当未配置 webhook secret 时,服务会接受未经校验的 webhook 请求,并据此修改匹配 GitRepo 资源的 spec.pollingInterval 字段。该问题仅影响 Fleet 0.16 至 0.16.2 之前的版本。
影响范围
SUSE Rancher Fleet 0.16 系列中 0.16.2 之前的版本;更早版本不受影响。
漏洞详情
漏洞类型为缺失身份验证/授权校验。webhook 服务在未设置 secret 时不会验证请求来源,处理请求时会按匹配规则更新 GitRepo 的 spec.pollingInterval 字段,且未限制目标命名空间。攻击者只需能访问该 webhook 服务即可触发,无需 Kubernetes 凭据。
利用条件与风险
利用前提是 webhook secret 未配置且攻击者具备对 webhook 服务的网络访问能力;成功利用可越权修改其无权访问的命名空间中的 GitRepo 配置,CVSS 5.4 属中危。
修复建议
升级至 SUSE Rancher Fleet 0.16.2 或更高版本;临时缓解措施为为 webhook 配置 secret 并限制 webhook 服务的网络访问。
A vulnerability was discovered in Fleet’s Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside
the namespaces they are authorized for. This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected.