Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2026-55175

HIGH · 7.5 CVSS Gepubliceerd: CWE-502

Beschrijving NL

Spinnaker is een open source, multi-cloud continuous delivery platform. Voorafgaand aan de versies 2026.1.1, 2026.0.3, 2025.4.4 en 2025.3.4 op hun respectieve vrijgavelijnen, staan Kustomize bakbewerkingen onveilige verwerking van YAML-tags toe in rosco-manifesten. Dit kan leiden tot het op afstand uitvoeren van code op rosco-pods bij het uitvoeren van Kustomize-bakken. Dit probleem is opgelost in versies 2026.1.1, 2026.0.3, 2025.4.4 en 2025.3.4.

Origineel (Engels) tonen

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code execution on rosco pods when performing Kustomize bakes. This issue is fixed in versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4.

Vendors

Linuxfoundation

Affected products

Spinnaker

References