CVE-2019-18658 – helm.sh/helm
Package
Manager: go
Name: helm.sh/helm
Vulnerable Version: >=2.0.0 <2.15.2
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.0057 pctl0.67638
Details
Helm Unsafe Link Following In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as `/etc/passwd`, or to execute a denial of service (DoS) via a special file such as /dev/urandom, via symlinks. No version of Tiller is known to be impacted. This is a client-only issue.
Metadata
Created: 2022-05-24T22:01:14Z
Modified: 2023-09-26T19:48:05Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-p5pc-m4q7-7qm9/GHSA-p5pc-m4q7-7qm9.json
CWE IDs: ["CWE-59"]
Alternative ID: GHSA-p5pc-m4q7-7qm9
Finding: F076
Auto approve: 1