Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9vp5-m38w-j776

Опубликовано: 24 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

Aliases are never checked in helm

Impact

During a security audit of Helm's code base, security researchers at Trail of Bits identified a bug in which the alias field on a Chart.yaml is not properly sanitized. This could lead to the injection of unwanted information into a chart.

Patches

This issue has been patched in Helm 3.3.2 and 2.16.11

Specific Go Packages Affected

helm.sh/helm/v3/pkg/chartutil

Workarounds

Manually review the dependencies field of any untrusted chart, verifying that the alias field is either not used, or (if used) does not contain newlines or path characters.

Пакеты

Наименование

helm.sh/helm/v3

go
Затронутые версииВерсия исправления

>= 3.0.0, < 3.3.2

3.3.2

Наименование

helm.sh/helm

go
Затронутые версииВерсия исправления

< 2.16.11

2.16.11

EPSS

Процентиль: 46%
0.00234
Низкий

3.7 Low

CVSS3

Дефекты

CWE-20
CWE-74

Связанные уязвимости

CVSS3: 2.7
redhat
больше 5 лет назад

In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the `dependencies` field of any untrusted chart, verifying that the `alias` field is either not used, or (if used) does not contain newlines or path characters.

CVSS3: 3.7
nvd
больше 5 лет назад

In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the `dependencies` field of any untrusted chart, verifying that the `alias` field is either not used, or (if used) does not contain newlines or path characters.

CVSS3: 3.7
debian
больше 5 лет назад

In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the ...

suse-cvrf
около 5 лет назад

Security changes in Kubernetes, etcd, and helm; Bugfix in cri-o package

EPSS

Процентиль: 46%
0.00234
Низкий

3.7 Low

CVSS3

Дефекты

CWE-20
CWE-74