Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2024-04524

Опубликовано: 14 фев. 2024
Источник: fstec
CVSS3: 6.4
CVSS2: 5.5
EPSS Низкий

Описание

Уязвимость пакетного менеджера для Kubernetes Helm связана с неверным ограничением имени пути к каталогу с ограниченным доступом. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, сохранить диаграмму Helm Chart за пределами ожидаемого каталога

Вендор

The Linux Foundation

Наименование ПО

Helm

Версия ПО

до 3.14.1 (Helm)

Тип ПО

Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 5,5)
Средний уровень опасности (базовая оценка CVSS 3.0 составляет 6,4)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://github.com/helm/helm/security/advisories/GHSA-v53g-5gjp-272r

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 38%
0.00168
Низкий

6.4 Medium

CVSS3

5.5 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.4
ubuntu
почти 2 года назад

Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save a chart whose name within the `Chart.yaml` file includes a relative path change, the chart would be saved outside its expected directory based on the changes in the relative path. The validation and linting did not detect the path changes in the name. This issue has been resolved in Helm v3.14.1. Users unable to upgrade should check all charts used by Helm for path changes in their name as found in the `Chart.yaml` file. This includes dependencies.

CVSS3: 6.4
redhat
почти 2 года назад

Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save a chart whose name within the `Chart.yaml` file includes a relative path change, the chart would be saved outside its expected directory based on the changes in the relative path. The validation and linting did not detect the path changes in the name. This issue has been resolved in Helm v3.14.1. Users unable to upgrade should check all charts used by Helm for path changes in their name as found in the `Chart.yaml` file. This includes dependencies.

CVSS3: 6.4
nvd
почти 2 года назад

Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save a chart whose name within the `Chart.yaml` file includes a relative path change, the chart would be saved outside its expected directory based on the changes in the relative path. The validation and linting did not detect the path changes in the name. This issue has been resolved in Helm v3.14.1. Users unable to upgrade should check all charts used by Helm for path changes in their name as found in the `Chart.yaml` file. This includes dependencies.

CVSS3: 6.4
msrc
больше 1 года назад

Dependency management path traversal in helm

CVSS3: 6.4
debian
почти 2 года назад

Helm is a tool for managing Charts. Charts are packages of pre-configu ...

EPSS

Процентиль: 38%
0.00168
Низкий

6.4 Medium

CVSS3

5.5 Medium

CVSS2