PT-2019-5658 · Helm+1 · Helm+1

Published

2019-01-14

·

Updated

2024-08-20

·

CVE-2019-1000008

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Helm versions 2.0.0 through 2.12.1
Description The issue is related to a path traversal vulnerability in Helm, where chart archive files can be unpacked outside of the target directory when using the commands helm fetch --untar and helm lint some.tgz. This can be exploited by a remote attacker who crafts a special chart archive, which can then be executed by running a Helm command. The vulnerability appears to have been fixed in version 2.12.2.
Recommendations For Helm versions 2.0.0 through 2.12.1, update to version 2.12.2 to resolve the issue. As a temporary workaround, consider avoiding the use of the helm fetch --untar and helm lint some.tgz commands until the update is applied.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1538
ALT-PU-2020-2339
BDU:2020-04871
CVE-2019-1000008
GHSA-XRXM-MVQM-R553
GO-2023-1948

Affected Products

Alt Linux
Helm