Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15185

Опубликовано: 18 сент. 2020
Источник: redhat
CVSS3: 2.7
EPSS Низкий

Описание

In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad chart into a repository. To perform this attack, an attacker must have write access to the index file (which can occur during a MITM attack on a non-SSL connection). This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the index file in the Helm repository cache before installing software.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2helmFix deferred
Red Hat OpenStack Platform 16.2osp-director-provisioner-containerNot affected
Red Hat OpenStack Platform 16.2rhosp-rhel8-tech-preview/osp-director-downloaderNot affected
Red Hat OpenStack Platform 16.2rhosp-rhel8-tech-preview/osp-director-operatorNot affected
Red Hat Advanced Cluster Management for Kubernetes 2acmesolver-containerFixedRHEA-2021:072904.03.2021
Red Hat Advanced Cluster Management for Kubernetes 2acm-must-gather-containerFixedRHEA-2021:072904.03.2021
Red Hat Advanced Cluster Management for Kubernetes 2acm-operator-bundle-containerFixedRHEA-2021:072904.03.2021
Red Hat Advanced Cluster Management for Kubernetes 2application-ui-containerFixedRHEA-2021:072904.03.2021
Red Hat Advanced Cluster Management for Kubernetes 2cainjector-containerFixedRHEA-2021:072904.03.2021
Red Hat Advanced Cluster Management for Kubernetes 2cert-manager-controller-containerFixedRHEA-2021:072904.03.2021

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1882306helm: write access to the index file allows an attacker to inject bad chart into repository

EPSS

Процентиль: 46%
0.00234
Низкий

2.7 Low

CVSS3

Связанные уязвимости

CVSS3: 2.2
nvd
больше 5 лет назад

In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad chart into a repository. To perform this attack, an attacker must have write access to the index file (which can occur during a MITM attack on a non-SSL connection). This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the index file in the Helm repository cache before installing software.

CVSS3: 2.2
debian
больше 5 лет назад

In Helm before versions 2.16.11 and 3.3.2, a Helm repository can conta ...

CVSS3: 2.2
github
больше 4 лет назад

Repository index file allows for duplicates of the same chart entry in helm

suse-cvrf
около 5 лет назад

Security changes in Kubernetes, etcd, and helm; Bugfix in cri-o package

EPSS

Процентиль: 46%
0.00234
Низкий

2.7 Low

CVSS3