PT-2024-2620 · Cloud Native Computing Foundation · Helm

Published

2024-03-03

·

Updated

2025-02-11

·

CVE-2019-25210

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Helm versions through 3.13.3
Description An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm where it displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. The vendor's position is that this behavior was introduced intentionally and cannot be removed without breaking backwards compatibility, as some users may be relying on these values. It is also noted that it is not the Helm Project's responsibility if a user decides to use --dry-run within a CI/CD environment whose output is visible to unauthorized persons.
Recommendations For Helm versions through 3.13.3, consider avoiding the use of the --dry-run flag in environments where the output may be visible to unauthorized persons, as a temporary workaround to minimize the risk of information disclosure. Restrict access to the CI/CD environment to prevent unauthorized persons from viewing the output of --dry-run calls. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-02687
CVE-2019-25210
GHSA-JW44-4F3J-Q396

Affected Products

Helm