VYPR
Medium severity5.0NVD Advisory· Published Oct 22, 2022· Updated Jun 17, 2026

CVE-2022-39272

CVE-2022-39272

Description

Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. This issue is patched in version 0.35.0. As a workaround, Admission controllers can be employed to restrict the values that can be used for fields .spec.interval and .spec.timeout, however upgrading to the latest versions is still the recommended mitigation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/fluxcd/flux2Go
>= 0.1.0, < 0.35.00.35.0
github.com/fluxcd/source-controllerGo
>= 0.0.1-alpha-1, < 0.30.00.30.0
github.com/fluxcd/kustomize-controllerGo
>= 0.0.1-alpha-1, < 0.29.00.29.0
github.com/fluxcd/helm-controllerGo
>= 0.0.1-alpha-1, < 0.24.00.24.0
github.com/fluxcd/notification-controllerGo
>= 0.0.1-alpha-1, < 0.27.00.27.0
github.com/fluxcd/image-automation-controllerGo
>= 0.1.0, < 0.26.00.26.0
github.com/fluxcd/image-reflector-controllerGo
>= 0.1.0, < 0.22.00.22.0
github.com/fluxcd/helm-controller/apiGo
< 0.26.00.26.0
github.com/fluxcd/image-automation-controller/apiGo
< 0.26.10.26.1
github.com/fluxcd/image-reflector-controller/apiGo
< 0.22.10.22.1
github.com/fluxcd/kustomize-controller/apiGo
< 0.30.00.30.0
github.com/fluxcd/notification-controller/apiGo
< 0.28.00.28.0
github.com/fluxcd/source-controller/apiGo
< 0.30.00.30.0

Affected products

63

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.