In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the `dependencies` field of any untrusted chart, verifying that the `alias` field is either not used, or (if used) does not contain newlines or path characters.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 08 Sep 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat acm
CPEs cpe:/a:redhat:acm:2.2::el7
Vendors & Products Redhat
Redhat acm

Mon, 19 Aug 2024 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.2::el7
cpe:/a:redhat:acm:2.2::el8
Vendors & Products Redhat
Redhat acm

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T13:08:22.470Z

Reserved: 2020-06-25T00:00:00

Link: CVE-2020-15184

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-17T21:15:17.550

Modified: 2024-11-21T05:05:01.673

Link: CVE-2020-15184

cve-icon Redhat

Severity : Low

Publid Date: 2020-09-18T00:00:00Z

Links: CVE-2020-15184 - Bugzilla

cve-icon OpenCVE Enrichment

No data.