Логотип exploitDog
bind:CVE-2023-25165
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-25165

Количество 9

Количество 9

redhat логотип

CVE-2023-25165

около 3 лет назад

Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with `helm install|upgrade|template` or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject `getHostByName` into a chart in order to disclose values to a malicious DNS server. The issue has been fixed in Helm 3.11.1. Prior to using a chart with Helm verify the `getHostByName` function is not being used in a template to disclose any information you do not want passed to DNS servers.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-25165

около 3 лет назад

Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with `helm install|upgrade|template` or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject `getHostByName` into a chart in order to disclose values to a malicious DNS server. The issue has been fixed in Helm 3.11.1. Prior to using a chart with Helm verify the `getHostByName` function is not being used in a template to disclose any information you do not want passed to DNS servers.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2023-25165

почти 3 года назад

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-25165

около 3 лет назад

Helm is a tool that streamlines installing and managing Kubernetes app ...

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2023:0064-1

почти 3 года назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2100-1

почти 3 года назад

Security update for terraform-provider-helm

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1752-1

почти 3 года назад

Security update for terraform-provider-helm

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1571-1

почти 3 года назад

Security update for helm

EPSS: Низкий
github логотип

GHSA-pwcw-6f5g-gxf8

около 3 лет назад

Helm vulnerable to information disclosure via getHostByName Function

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-25165

Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with `helm install|upgrade|template` or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject `getHostByName` into a chart in order to disclose values to a malicious DNS server. The issue has been fixed in Helm 3.11.1. Prior to using a chart with Helm verify the `getHostByName` function is not being used in a template to disclose any information you do not want passed to DNS servers.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25165

Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with `helm install|upgrade|template` or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject `getHostByName` into a chart in order to disclose values to a malicious DNS server. The issue has been fixed in Helm 3.11.1. Prior to using a chart with Helm verify the `getHostByName` function is not being used in a template to disclose any information you do not want passed to DNS servers.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 4.3
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-25165

Helm is a tool that streamlines installing and managing Kubernetes app ...

CVSS3: 4.3
0%
Низкий
около 3 лет назад
suse-cvrf логотип
openSUSE-SU-2023:0064-1

Security update for trivy

0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:2100-1

Security update for terraform-provider-helm

0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:1752-1

Security update for terraform-provider-helm

0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:1571-1

Security update for helm

0%
Низкий
почти 3 года назад
github логотип
GHSA-pwcw-6f5g-gxf8

Helm vulnerable to information disclosure via getHostByName Function

CVSS3: 4.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу