Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9f8-9pmf-xv68

Опубликовано: 14 авг. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Helm May Panic Due To Incorrect YAML Content

A Helm contributor discovered an improper validation of type error when parsing Chart.yaml and index.yaml files that can lead to a panic.

Impact

There are two areas of YAML validation that were impacted. First, when a Chart.yaml file had a null maintainer or the child or parent of a dependencies import-values could be parsed as something other than a string, helm lint would panic. Second, when an index.yaml had an empty entry in the list of chart versions Helm would panic on interactions with that repository.

Patches

This issue has been resolved in Helm v3.18.5.

Workarounds

Ensure YAML files are formatted as Helm expects prior to processing them with Helm.

References

Helm's security policy is spelled out in detail in our SECURITY document.

Credits

Disclosed by Jakub Ciolek at AlphaSense.

Пакеты

Наименование

helm.sh/helm/v3

go
Затронутые версииВерсия исправления

< 3.18.5

3.18.5

EPSS

Процентиль: 2%
0.00015
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 6.5
redhat
27 дней назад

Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml files, an improper validation of type error can lead to a panic. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring YAML files are formatted as Helm expects prior to processing them with Helm.

CVSS3: 6.5
nvd
27 дней назад

Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml files, an improper validation of type error can lead to a panic. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring YAML files are formatted as Helm expects prior to processing them with Helm.

CVSS3: 6.5
debian
27 дней назад

Helm is a package manager for Charts for Kubernetes. Prior to version ...

EPSS

Процентиль: 2%
0.00015
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-908