PT-2019-5658 · Helm+1 · Helm+1
CVE-2019-1000008
·
Publicado
2019-01-14
·
Atualizado
2024-08-20
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Helm versions 2.0.0 through 2.12.1
Description
The issue is related to a path traversal vulnerability in Helm, where chart archive files can be unpacked outside of the target directory when using the commands
helm fetch --untar and helm lint some.tgz. This can be exploited by a remote attacker who crafts a special chart archive, which can then be executed by running a Helm command. The vulnerability appears to have been fixed in version 2.12.2.Recommendations
For Helm versions 2.0.0 through 2.12.1, update to version 2.12.2 to resolve the issue.
As a temporary workaround, consider avoiding the use of the
helm fetch --untar and helm lint some.tgz commands until the update is applied.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Helm