Логотип exploitDog
bind:CVE-2020-15184
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15184

Количество 5

Количество 5

redhat логотип

CVE-2020-15184

больше 5 лет назад

In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the `dependencies` field of any untrusted chart, verifying that the `alias` field is either not used, or (if used) does not contain newlines or path characters.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2020-15184

больше 5 лет назад

In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the `dependencies` field of any untrusted chart, verifying that the `alias` field is either not used, or (if used) does not contain newlines or path characters.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2020-15184

больше 5 лет назад

In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the ...

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-9vp5-m38w-j776

больше 4 лет назад

Aliases are never checked in helm

CVSS3: 3.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:3760-1

около 5 лет назад

Security changes in Kubernetes, etcd, and helm; Bugfix in cri-o package

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-15184

In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the `dependencies` field of any untrusted chart, verifying that the `alias` field is either not used, or (if used) does not contain newlines or path characters.

CVSS3: 2.7
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-15184

In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the `dependencies` field of any untrusted chart, verifying that the `alias` field is either not used, or (if used) does not contain newlines or path characters.

CVSS3: 3.7
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-15184

In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the ...

CVSS3: 3.7
0%
Низкий
больше 5 лет назад
github логотип
GHSA-9vp5-m38w-j776

Aliases are never checked in helm

CVSS3: 3.7
0%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2020:3760-1

Security changes in Kubernetes, etcd, and helm; Bugfix in cri-o package

около 5 лет назад

Уязвимостей на страницу