Логотип exploitDog
bind:CVE-2020-15185
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15185

Количество 5

Количество 5

redhat логотип

CVE-2020-15185

больше 5 лет назад

In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad chart into a repository. To perform this attack, an attacker must have write access to the index file (which can occur during a MITM attack on a non-SSL connection). This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the index file in the Helm repository cache before installing software.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2020-15185

больше 5 лет назад

In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad chart into a repository. To perform this attack, an attacker must have write access to the index file (which can occur during a MITM attack on a non-SSL connection). This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the index file in the Helm repository cache before installing software.

CVSS3: 2.2
EPSS: Низкий
debian логотип

CVE-2020-15185

больше 5 лет назад

In Helm before versions 2.16.11 and 3.3.2, a Helm repository can conta ...

CVSS3: 2.2
EPSS: Низкий
github логотип

GHSA-jm56-5h66-w453

больше 4 лет назад

Repository index file allows for duplicates of the same chart entry in helm

CVSS3: 2.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:3760-1

около 5 лет назад

Security changes in Kubernetes, etcd, and helm; Bugfix in cri-o package

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-15185

In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad chart into a repository. To perform this attack, an attacker must have write access to the index file (which can occur during a MITM attack on a non-SSL connection). This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the index file in the Helm repository cache before installing software.

CVSS3: 2.7
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-15185

In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad chart into a repository. To perform this attack, an attacker must have write access to the index file (which can occur during a MITM attack on a non-SSL connection). This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the index file in the Helm repository cache before installing software.

CVSS3: 2.2
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-15185

In Helm before versions 2.16.11 and 3.3.2, a Helm repository can conta ...

CVSS3: 2.2
0%
Низкий
больше 5 лет назад
github логотип
GHSA-jm56-5h66-w453

Repository index file allows for duplicates of the same chart entry in helm

CVSS3: 2.2
0%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2020:3760-1

Security changes in Kubernetes, etcd, and helm; Bugfix in cri-o package

около 5 лет назад

Уязвимостей на страницу