Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23526

Опубликовано: 15 дек. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that can cause a segmentation violation. The chartutil package contains a parser that loads a JSON Schema validation file. For example, the Helm client when rendering a chart will validate its values with the schema file. The chartutil package parses the schema file and loads it into structures Go can work with. Some schema files can cause array data structures to be created causing a memory violation. Applications that use the chartutil package in the Helm SDK to parse a schema file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. Helm is not a long running service so the panic will not affect future uses of the Helm client. This issue has been patched in 3.10.3. SDK users can validate schema files that are correctly formatted before passing them to the chartutil functions.

A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that could cause a segmentation violation. The chartutil package contains a parser that loads a JSON Schema validation files into structures Go can work with. Some schema files can cause array data structures to be created, causing a memory violation. Applications that use the chartutil package in the Helm SDK to parse a schema files may result in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Will not fix
Cryostat 2cryostat-tech-preview/cryostat-rhel8-operatorNot affected
OpenShift Developer Tools and ServiceshelmAffected
OpenShift Developer Tools and Servicesjenkins-operator-containerWill not fix
OpenShift Serverlessopenshift-serverless-1/ingress-rhel8-operatorWill not fix
OpenShift Service Mesh 2openshift-service-mesh/istio-cni-rhel8Will not fix
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorWill not fix
OpenShift Service Mesh 2.1servicemeshWill not fix
Red Hat 3scale API Management Platform 23scale-operator-containerAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-rhel8Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2154196helm: Denial of service through schema file

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 3 лет назад

Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that can cause a segmentation violation. The _chartutil_ package contains a parser that loads a JSON Schema validation file. For example, the Helm client when rendering a chart will validate its values with the schema file. The _chartutil_ package parses the schema file and loads it into structures Go can work with. Some schema files can cause array data structures to be created causing a memory violation. Applications that use the _chartutil_ package in the Helm SDK to parse a schema file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. Helm is not a long running service so the panic will not affect future uses of the Helm client. This issue has been patched in 3.10.3. SDK users can validate schema files that are correctly formatted before passing them to the _chartutil_ functions

CVSS3: 7.5
msrc
около 3 лет назад

Helm contains Denial of service through schema file

CVSS3: 5.3
debian
около 3 лет назад

Helm is a tool for managing Charts, pre-configured Kubernetes resource ...

CVSS3: 5.3
github
около 3 лет назад

Helm vulnerable to denial of service through schema file

suse-cvrf
около 3 лет назад

Security update for helm

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3