Horizon Alert
Summary of the vulnerability and why it matters
This advisory describes a vulnerability in Woodpecker, a CI/CD engine, that could allow an authenticated user with repository push permissions to run pipeline code with elevated privileges, potentially leading to the exfiltration of sensitive data or cluster takeover. The issue stems from how the system handles service account credentials in its Kubernetes backend.
- Users with push access can abuse service accounts.
- This could compromise sensitive data and cluster control.
- Confirm relevance and assess potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker with repository push access can leverage this vulnerability in Woodpecker CI/CD to compromise the entire cluster. By creating a malicious pipeline, they can manipulate the Kubernetes backend options to specify any ServiceAccount. This allows the pipeline pods to run under the permissions of the chosen ServiceAccount, potentially granting the attacker elevated privileges and access to sensitive information.
- Requires repository push permission.
- Pipeline configuration triggers vulnerability.
- Risk of secret exfiltration and cluster takeover.
Live Threat
Current exploitation, exposure, and threat context
A user with push permissions on a connected repository could exploit this vulnerability to run pipeline pods under an arbitrary ServiceAccount. When a privileged ServiceAccount is reachable, an attacker may exfiltrate secrets or take over the cluster.
- Service Account and RBAC permissions.
- Unauthorized pipeline pod execution.
- Potential cluster takeover or data exfiltration.
Operational Fix
Recommended remediation, mitigation, and detection steps
Responsible teams likely include platform engineering and security operations, who manage the CI/CD infrastructure and its integrations, alongside application owners who may provision or utilize the Woodpecker engine. The initial step is to inventory all Woodpecker deployments, assess their network exposure and criticality, identify the accountable owners for each instance, and then prioritize remediation based on potential impact, considering the need for vendor coordination or temporary risk mitigation.
- Platform and security teams own the issue.
- Verify Woodpecker deployment reachability and criticality.
- Plan remediation or coordinate vendor updates.