Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23524

Опубликовано: 15 дек. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, resulting in Denial of Service. Input to functions in the strvals package can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the strvals package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. This issue has been patched in 3.10.3. SDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the strvals functions.

A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption. Input to functions in the strvals package could cause a stack overflow that is unrecoverable by Go. Applications that use functions from the strvals package in Helm SDK may result in a denial of service.

Меры по смягчению последствий

SDK users can validate strings supplied by users that won't create large arrays causing significant memory usage before passing them to the strvals functions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Will not fix
Cryostat 2cryostat-tech-preview/cryostat-rhel8-operatorNot affected
OpenShift Developer Tools and Servicesjenkins-operator-containerWill not fix
OpenShift Serverlessopenshift-serverless-1/ingress-rhel8-operatorWill not fix
Red Hat 3scale API Management Platform 23scale-operator-containerAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-rhel8Will not fix
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-central-db-rhel8Affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-docs-rhel8Affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-rhel8-operatorAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2154200helm: Denial of service through string value parsing

EPSS

Процентиль: 21%
0.00069
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 3 лет назад

Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, resulting in Denial of Service. Input to functions in the _strvals_ package can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the _strvals_ package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. This issue has been patched in 3.10.3. SDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the _strvals_ functions.

CVSS3: 7.5
msrc
около 3 лет назад

Helm vulnerable to Denial of service through string value parsing

CVSS3: 5.3
debian
около 3 лет назад

Helm is a tool for managing Charts, pre-configured Kubernetes resource ...

CVSS3: 5.3
github
около 3 лет назад

Helm vulnerable to denial of service through string value parsing

suse-cvrf
около 3 лет назад

Security update for helm

EPSS

Процентиль: 21%
0.00069
Низкий

7.5 High

CVSS3