CVE-2022-24878 - CVE House
Back to Database
Status published High CVE-2022-24878

Improper path handling in Kustomization files allows for denial of service

Vulnerability Description

Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to cause a Denial of Service at the controller level. Workarounds include automated tooling in the user's CI/CD pipeline to validate `kustomization.yaml` files conform with specific policies. This vulnerability is fixed in kustomize-controller v0.24.0 and included in flux2 v0.29.0. Users are recommended to upgrade.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-24878

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

flux2
Vulnerable Versions:
flux2 < v0.28.5, >= v0.19.0, kustomize < v0.29.0, >= v0.16.0

Timeline

Official Publish: May 6th, 2022
Last Modified: April 23rd, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Weaknesses (CWE)