Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-4053

Опубликовано: 16 июн. 2020
Источник: redhat
CVSS3: 6.4
EPSS Низкий

Описание

In Helm greater than or equal to 3.0.0 and less than 3.2.4, a path traversal attack is possible when installing Helm plugins from a tar archive over HTTP. It is possible for a malicious plugin author to inject a relative path into a plugin archive, and copy a file outside of the intended directory. This has been fixed in 3.2.4.

A flaw was found in the Helm plugin installation, where it was vulnerable to path traversal attacks. This flaw allows an attacker to create specially crafted plugin archives to create files outside of the plugin directory. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2osp-director-provisioner-containerNot affected
Red Hat OpenStack Platform 16.2rhosp-rhel8-tech-preview/osp-director-downloaderNot affected
Red Hat OpenStack Platform 16.2rhosp-rhel8-tech-preview/osp-director-operatorNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1848497helm: allows path traversal when installing plugins from a tar archive over HTTP

EPSS

Процентиль: 61%
0.00408
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.7
nvd
больше 5 лет назад

In Helm greater than or equal to 3.0.0 and less than 3.2.4, a path traversal attack is possible when installing Helm plugins from a tar archive over HTTP. It is possible for a malicious plugin author to inject a relative path into a plugin archive, and copy a file outside of the intended directory. This has been fixed in 3.2.4.

CVSS3: 3.7
debian
больше 5 лет назад

In Helm greater than or equal to 3.0.0 and less than 3.2.4, a path tra ...

CVSS3: 3.7
github
больше 4 лет назад

Plugin archive directory traversal in Helm

EPSS

Процентиль: 61%
0.00408
Низкий

6.4 Medium

CVSS3