Vulnerability GHSA-q7hv-xx6h-q2x8
Summary
External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration
Details
Summary
A bug in the webhook generator initialization order incorrectly cleared the label-enforcement flag (EnforceLabels) after it was set, resulting in the provider-side check for external-secrets.io/type=webhook being skipped (and the operation to succeed while it should have failed with secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook.
Impact
A user with the permission to create webhook generator can set the webhook generator to a victim' secret (which was not previously labelled for webhook's use), and exfiltrate it to a malicious URL.
Mitigations
Until you upgrade, you can reduce risk by:
- disabling webhook generators if not needed (or denying
generators.external-secrets.io/v1alpha1Webhookvia an admission policy); - restricting RBAC: limit who can create generators of kind
Webhook; - enforcing an admission policy (OPA Gatekeeper / Kyverno) requiring referenced secrets to be labeled
external-secrets.io/type=webhook; - restricting egress from external-secrets controller pods to an allowlist (kubernetes
NetworkPolicy/ service mesh egress policy).
References
- PR #5901 (fix: webhook initialization order)
Related Vulnerabilities
Other vulnerabilities affecting the same packages