GHSA-p5pc-m4q7-7qm9

Suggest an improvement
Source
https://github.com/advisories/GHSA-p5pc-m4q7-7qm9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-p5pc-m4q7-7qm9/GHSA-p5pc-m4q7-7qm9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p5pc-m4q7-7qm9
Aliases
Published
2022-05-24T22:01:14Z
Modified
2024-08-20T20:59:17.779143Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Helm Unsafe Link Following
Details

In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd, or to execute a denial of service (DoS) via a special file such as /dev/urandom, via symlinks. No version of Tiller is known to be impacted. This is a client-only issue.

References

Affected packages

Go / helm.sh/helm

Package

Name
helm.sh/helm
View open source insights on deps.dev
Purl
pkg:golang/helm.sh/helm

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0
Fixed
2.15.2