Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-15184

Опубликовано: 17 сент. 2020
Источник: nvd
CVSS3: 3.7
CVSS3: 2.7
CVSS2: 4
EPSS Низкий

Описание

In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the alias field on a Chart.yaml is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the dependencies field of any untrusted chart, verifying that the alias field is either not used, or (if used) does not contain newlines or path characters.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.16.11 (исключая)
cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.3.2 (исключая)

EPSS

Процентиль: 46%
0.00234
Низкий

3.7 Low

CVSS3

2.7 Low

CVSS3

4 Medium

CVSS2

Дефекты

CWE-20
CWE-74

Связанные уязвимости

CVSS3: 2.7
redhat
больше 5 лет назад

In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the `dependencies` field of any untrusted chart, verifying that the `alias` field is either not used, or (if used) does not contain newlines or path characters.

CVSS3: 3.7
debian
больше 5 лет назад

In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the ...

CVSS3: 3.7
github
больше 4 лет назад

Aliases are never checked in helm

suse-cvrf
около 5 лет назад

Security changes in Kubernetes, etcd, and helm; Bugfix in cri-o package

EPSS

Процентиль: 46%
0.00234
Низкий

3.7 Low

CVSS3

2.7 Low

CVSS3

4 Medium

CVSS2

Дефекты

CWE-20
CWE-74