PT-2020-14255 · Helm+2 · Helm+2

Published

2020-09-17

·

Updated

2024-03-06

·

CVE-2020-15184

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Helm versions prior to 2.16.11 Helm versions prior to 3.3.2
Description The issue is related to the alias field on a Chart.yaml not being properly sanitized, which could lead to the injection of unwanted information into a chart. This was identified during a security audit of Helm's code base.
Recommendations For Helm versions prior to 2.16.11, update to version 2.16.11 to resolve the issue. For Helm versions prior to 3.3.2, update to version 3.3.2 to resolve the issue. As a temporary workaround, consider manually reviewing the dependencies field of any untrusted chart, verifying that the alias field is either not used, or (if used) does not contain newlines or path characters.

Fix

RCE

Special Elements Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3396
ALT-PU-2020-3416
ALT-PU-2022-1250
BIT-HELM-2020-15184
CVE-2020-15184
GHSA-9VP5-M38W-J776
SUSE-SU-2020:3760-1

Affected Products

Alt Linux
Helm
Suse