github.com/tektoncd/pipeline is vulnerable to Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
75
High Risk
An improper input validation issue in Tekton Pipelines git resolver allowed user-controlled revision values beginning with - to be passed directly to git fetch, enabling injection of arbitrary Git command-line flags such as --upload-pack. Because local filesystem repository paths were also accepted as valid URLs, an attacker able to create ResolutionRequest objects could trigger execution of arbitrary binaries on the resolver pod. Since the tekton-pipelines-resolvers ServiceAccount had cluster-wide access to read Secrets, successful exploitation could lead to remote code execution, full cluster secret exfiltration, and privilege escalation.
You are affected if you are using a version that falls within the vulnerable range.
github.com/tektoncd/pipeline is vulnerable to Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in versions 1.10.0 - 1.11.0, 1.7.0 - 1.9.2, 1.4.0 - 1.6.1, 1.2.28 - 1.3.3 and 1.0.0 - 1.0.1.
Upgrade the github.com/tektoncd/pipeline library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant