CVE-2022-39272
Flux2 vulnerable to Denial of Service due to Improper use of metav1.Duration
Description
Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or `.spec.timeout` (and structured variations of these fields), causing the entire object type to stop being processed. This issue is patched in version 0.35.0. As a workaround, Admission controllers can be employed to restrict the values that can be used for fields `.spec.interval` and `.spec.timeout`, however upgrading to the latest versions is still the recommended mitigation.
How to fix CVE-2022-39272
To remediate CVE-2022-39272, upgrade the affected package to a fixed version below.
- —upgrade to 0.35.0 or later
- —upgrade to 0.29.0 or later
- —upgrade to 0.35.0 or later
- —upgrade to 0.24.0 or later
- —upgrade to 0.26.0 or later
- —upgrade to 0.26.0 or later
- —upgrade to 0.26.0 or later
- —upgrade to 0.26.1 or later
- —upgrade to 0.26.1 or later
- —upgrade to 0.22.0 or later
- —upgrade to 0.22.1 or later
- —upgrade to 0.22.1 or later
- —upgrade to 0.29.0 or later
- —upgrade to 0.30.0 or later
Is CVE-2022-39272 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (21)
- >= 0.1.0, < 0.35.0
- >= 0.0.2, < 0.29.0
- >= 0.1.0, < 0.35.0
- >= 0.0.1-alpha-1, < 0.24.0
- from 0, < 0.26.0
- from 0, < 0.26.0
- >= 0.1.0, < 0.26.0
- from 0, < 0.26.1
- from 0, < 0.26.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.0 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L |