SCA: security update for github.com/fluxcd/flux2, github.com/fluxcd/helm-controller, github.com/fluxcd/kustomize-controller (GHSA-vvmq-fwmg-2gjc)

critical Tenable Self-Hosted Container Security Plugin ID 419552

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0
and 0.29.0, helm-controller 0.1.0 to v0.19.0, and kustomize-controller 0.1.0 to v0.23.0 are vulnerable to
Code Injection via malicious Kubeconfig. In multi-tenancy deployments this can also lead to privilege
escalation if the controller's service account has elevated permissions. Workarounds include disabling
functionality via Validating Admission webhooks by restricting users from setting the `spec.kubeConfig`
field in Flux `Kustomization` and `HelmRelease` objects. Additional mitigations include applying
restrictive AppArmor and SELinux profiles on the controller’s pod to limit what binaries can be executed.
This vulnerability is fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in
flux2 v0.29.0 (CVE-2022-24817)

See Also

https://github.com/advisories/GHSA-vvmq-fwmg-2gjc

Plugin Details

Severity: Critical

ID: 419552

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 95.11

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2022-24817

CVSS v3

Risk Factor: Critical

Base Score: 9.9

Temporal Score: 8.6

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/16/2022

Vulnerability Publication Date: 5/6/2022

Reference Information

CVE: CVE-2022-24817

cwe: CWE-94