Helm does not sanitize all fields read from repository data files. A maliciously crafted data file may contain strings containing arbitrary data. If printed to a terminal, a malicious string could obscure or alter data on the screen.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-1040" }
{ "imports": [ { "path": "helm.sh/helm/v3/pkg/chart", "symbols": [ "Chart.Validate", "Metadata.Validate" ] }, { "path": "helm.sh/helm/v3/pkg/plugin", "symbols": [ "FindPlugins", "LoadAll", "LoadDir", "validatePluginData" ] }, { "path": "helm.sh/helm/v3/pkg/repo", "symbols": [ "ChartRepository.DownloadIndexFile", "ChartRepository.Index", "ChartRepository.Load", "FindChartInAuthAndTLSRepoURL", "FindChartInAuthRepoURL", "FindChartInRepoURL", "IndexDirectory", "IndexFile.Add", "LoadIndexFile", "loadIndex" ] } ] }