PT-2020-14255 · Helm+2 · Helm+2
Published
2020-09-17
·
Updated
2024-03-06
·
CVE-2020-15184
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Helm versions prior to 2.16.11
Helm versions prior to 3.3.2
Description
The issue is related to the
alias field on a Chart.yaml not being properly sanitized, which could lead to the injection of unwanted information into a chart. This was identified during a security audit of Helm's code base.Recommendations
For Helm versions prior to 2.16.11, update to version 2.16.11 to resolve the issue.
For Helm versions prior to 3.3.2, update to version 3.3.2 to resolve the issue.
As a temporary workaround, consider manually reviewing the
dependencies field of any untrusted chart, verifying that the alias field is either not used, or (if used) does not contain newlines or path characters.Fix
RCE
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Helm
Suse