In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad chart into a repository. To perform this attack, an attacker must have write access to the index file (which can occur during a MITM attack on a non-SSL connection). This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the index file in the Helm repository cache before installing software.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-1119 In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad chart into a repository. To perform this attack, an attacker must have write access to the index file (which can occur during a MITM attack on a non-SSL connection). This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the index file in the Helm repository cache before installing software.
Github GHSA Github GHSA GHSA-jm56-5h66-w453 Repository index file allows for duplicates of the same chart entry in helm
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 08 Sep 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat acm
CPEs cpe:/a:redhat:acm:2.2::el7
Vendors & Products Redhat
Redhat acm

Mon, 19 Aug 2024 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.2::el7
cpe:/a:redhat:acm:2.2::el8
Vendors & Products Redhat
Redhat acm

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T13:08:22.474Z

Reserved: 2020-06-25T00:00:00

Link: CVE-2020-15185

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-17T22:15:12.443

Modified: 2024-11-21T05:05:01.830

Link: CVE-2020-15185

cve-icon Redhat

Severity : Low

Publid Date: 2020-09-18T00:00:00Z

Links: CVE-2020-15185 - Bugzilla

cve-icon OpenCVE Enrichment

No data.