PT-2019-5658 · Helm+1 · Helm+1

CVE-2019-1000008

·

Publicado

2019-01-14

·

Atualizado

2024-08-20

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Helm versions 2.0.0 through 2.12.1
Description The issue is related to a path traversal vulnerability in Helm, where chart archive files can be unpacked outside of the target directory when using the commands helm fetch --untar and helm lint some.tgz. This can be exploited by a remote attacker who crafts a special chart archive, which can then be executed by running a Helm command. The vulnerability appears to have been fixed in version 2.12.2.
Recommendations For Helm versions 2.0.0 through 2.12.1, update to version 2.12.2 to resolve the issue. As a temporary workaround, consider avoiding the use of the helm fetch --untar and helm lint some.tgz commands until the update is applied.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-1538
ALT-PU-2020-2339
BDU:2020-04871
CVE-2019-1000008
GHSA-XRXM-MVQM-R553
GO-2023-1948

Produtos afetados

Alt Linux
Helm