Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jw44-4f3j-q396

Опубликовано: 03 мар. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Withdrawn Advisory: Helm shows secrets in clear text

Withdrawn Advisory

This advisory has been withdrawn because the issue describes intended behavior and the output is not exposed to unauthorized users. This link has been maintained to preserve external references.

Original Description

An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor's position is that this behavior was introduced intentionally, and cannot be removed without breaking backwards compatibility (some users may be relying on these values).

Пакеты

Наименование

helm.sh/helm/v3

go
Затронутые версииВерсия исправления

>= 3.0.0, <= 3.14.2

Отсутствует

EPSS

Процентиль: 50%
0.0068
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
redhat
больше 2 лет назад

An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor's position is that this behavior was introduced intentionally, and cannot be removed without breaking backwards compatibility (some users may be relying on these values). Also, it is not the Helm Project's responsibility if a user decides to use --dry-run within a CI/CD environment whose output is visible to unauthorized persons.

CVSS3: 6.5
nvd
больше 2 лет назад

An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor's position is that this behavior was introduced intentionally, and cannot be removed without breaking backwards compatibility (some users may be relying on these values). Also, it is not the Helm Project's responsibility if a user decides to use --dry-run within a CI/CD environment whose output is visible to unauthorized persons.

CVSS3: 6.5
debian
больше 2 лет назад

An issue was discovered in Cloud Native Computing Foundation (CNCF) He ...

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость пакетного менеджера для Kubernetes Helm, связанная с отсутствием защиты служебных данных, позволяющая нарушителю оказать влияние на конфиденциальность информации

EPSS

Процентиль: 50%
0.0068
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200