CVE-2022-39272
Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or `.spec.timeout` (and structured variations of these fields), causing the entire object type to stop being processed. This issue is patched in version 0.35.0. As a workaround, Admission controllers can be employed to restrict the values that can be used for fields `.spec.interval` and `.spec.timeout`, however upgrading to the latest versions is still the recommended mitigation.
Published:Oct 21, 2022
Last Modified:Apr 23, 2025
EPS:Oct 21, 2022
EPSS Score:0.0005
CVSS Score:5
Affected Products
Vendor
Product
Action
Vendor
Fluxcd
Product
Flux2
Fluxcd
Flux2
Vendor
Fluxcd
Product
Helm-controller
Fluxcd
Helm-controller
Vendor
Fluxcd
Product
Image-automation-controller
Fluxcd
Image-automation-controller
Vendor
Fluxcd
Product
Image-reflector-controller
Fluxcd
Image-reflector-controller
Vendor
Fluxcd
Product
Kustomize-controller
Fluxcd
Kustomize-controller
Vendor
Fluxcd
Product
Notification-controller
Fluxcd
Notification-controller
Vendor
Fluxcd
Product
Source-controller
Fluxcd
Source-controller
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
