GHSA-q7hv-xx6h-q2x8: High severity go/github.com/external-secrets/external-secrets vulnerability
Summary A bug in the webhook generator initialization order incorrectly cleared the label-enforcement flag (EnforceLabels) after it was set, resulting in the provider-side check for external-secrets.io/type=webhook being skipped (and the operation to succeed while it should have failed with secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook.
Impact A user with the permission to create webhook generator can set the webhook generator to a victim' secret (which was not previously labelled for webhook's use), and exfiltrate it to a malicious URL.
Mitigations Until you upgrade, you can reduce risk by: - disabling webhook generators if not needed (or denying generators.external-secrets.io/v1alpha1 Webhook via an admission policy); - restricting RBAC: limit who can create generators of kind Webhook; - enforcing an admission policy (OPA Gatekeeper / Kyverno) requiring referenced secrets to be labeled external-secrets.io/type=webhook; - restricting egress from external-secrets controller pods to an allowlist (kubernetes NetworkPolicy / service mesh egress policy).
References - PR #5901 (fix: webhook initialization order)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/external-secrets/external-secretsto a version that resolves this vulnerability.Fixed in 1.3.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PR #5901 - Configuration
Disable webhook generators if they are not needed.
external-secrets webhook generators webhook generators = disabled - Configuration
Deny generators.external-secrets.io/v1alpha1 Webhook via an admission policy.
admission policy allowed resource kind = deny generators.external-secrets.io/v1alpha1 Webhook - Configuration
Enforce an admission policy requiring referenced secrets to be labeled external-secrets.io/type=webhook.
OPA Gatekeeper / Kyverno required secret label = external-secrets.io/type=webhook - Configuration
Update the secret label to external-secrets.io/type=webhook before using it with the webhook generator.
referenced secret external-secrets.io/type = webhook - Compensating control
Restrict RBAC so that only authorized users can create generators of kind Webhook.
- Compensating control
Restrict egress from external-secrets controller pods to an allowlist using Kubernetes NetworkPolicy or a service mesh egress policy.
Event History
Frequently Asked Questions
Who can exploit this issue in a cluster?
A user who has permission to create webhook generators can exploit it. They can configure a webhook generator to use a victim secret that is not labeled for webhook use and send its contents to a malicious URL.
Is a secret label still enforced for webhook generator references?
No. The affected initialization order clears the EnforceLabels setting after it is configured, so the provider-side check for the external-secrets.io/type=webhook label is skipped.
What can be done if an upgrade cannot be applied immediately?
Disable webhook generators if they are not needed, or deny Webhook resources in generators.external-secrets.io/v1alpha1 through an admission policy. Also restrict RBAC for creating Webhook generators, require referenced secrets to carry external-secrets.io/type=webhook through OPA Gatekeeper or Kyverno, and restrict controller-pod egress to an allowlist.