Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-25210

Опубликовано: 03 мар. 2024
Источник: redhat
CVSS3: 6.5

Описание

An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor's position is that this behavior was introduced intentionally, and cannot be removed without breaking backwards compatibility (some users may be relying on these values). Also, it is not the Helm Project's responsibility if a user decides to use --dry-run within a CI/CD environment whose output is visible to unauthorized persons.

A vulnerability was found in Helm that may lead to sensitive information disclosure. When the --dry-run flag is used in Helm 3, it displays values of secrets. Helm 2 just displays the fact that a secret has been created.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Not affected
OpenShift Service Mesh 2openshift-service-mesh/istio-cni-rhel8Not affected
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-governance-policy-addon-controller-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-search-v2-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-volsync-addon-controller-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/multiclusterhub-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/multicluster-operators-channel-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/multicluster-operators-subscription-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/submariner-rhel9-operatorNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2268201helm: shows secrets with --dry-run option in clear text

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor's position is that this behavior was introduced intentionally, and cannot be removed without breaking backwards compatibility (some users may be relying on these values). Also, it is not the Helm Project's responsibility if a user decides to use --dry-run within a CI/CD environment whose output is visible to unauthorized persons.

CVSS3: 6.5
debian
больше 2 лет назад

An issue was discovered in Cloud Native Computing Foundation (CNCF) He ...

CVSS3: 6.5
github
больше 2 лет назад

Withdrawn Advisory: Helm shows secrets in clear text

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость пакетного менеджера для Kubernetes Helm, связанная с отсутствием защиты служебных данных, позволяющая нарушителю оказать влияние на конфиденциальность информации

6.5 Medium

CVSS3