Skip to content

x/vulndb: potential Go vuln in github.com/kcp-dev/kcp: GHSA-q6hv-wcjr-wp8h #3985

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-q6hv-wcjr-wp8h references a vulnerability in the following Go modules:

Module
github.com/kcp-dev/kcp

Description:

Impact

Because UPDATE validation is not being applied, it is possible for an actor with access to an instance of the initializingworkspaces virtual workspace to run arbitrary patches on the status field of LogicalCluster objects while the workspace is initializing.

This allows to add or remove any initializers as well as changing the phase of a LogicalCluster (to "Ready" for example).

As this effectively allows to skip certain initializers or the entire initialization phase, potential integrations with e...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/kcp-dev/kcp
      non_go_versions:
        - introduced: TODO (earliest fixed "0.28.3", vuln range "<= 0.28.1")
      vulnerable_at: 0.28.3
summary: |-
    kcp is missing update validation allows arbitrary LogicalCluster status patches
    through initializingworkspaces Virtual Workspace in github.com/kcp-dev/kcp
ghsas:
    - GHSA-q6hv-wcjr-wp8h
references:
    - advisory: https://github.com/advisories/GHSA-q6hv-wcjr-wp8h
    - advisory: https://github.com/kcp-dev/kcp/security/advisories/GHSA-q6hv-wcjr-wp8h
    - fix: https://github.com/kcp-dev/kcp/commit/02134a2a51d33652ab288cccd7a13539b59c7584
    - fix: https://github.com/kcp-dev/kcp/pull/3599
    - web: https://github.com/kcp-dev/kcp/releases/tag/v0.28.3
source:
    id: GHSA-q6hv-wcjr-wp8h
    created: 2025-09-26T15:01:26.934542827Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions