GHSA-qq3j-xp49-j73f

    Dashboard / Vulnerabilities / GHSA-qq3j-xp49-j73f

    GHSA-qq3j-xp49-j73f

    Published: 23 Jun 2021Last Modified: 8 Jul 2026

    Summary: Plugin archive directory traversal in Helm

    Details: The Helm core maintainers have identified an information disclosure vulnerability in Helm 3.0.0-3.2.3. ### Impact A traversal attack is possible when installing Helm plugins from a tar archive over HTTP. It is possible for a malicious plugin author to inject a relative path into a plugin archive, and copy a file outside of the intended directory. Traversal Attacks are a form of a Directory Traversal that can be exploited by extracting files from an archive. The premise of the Directory Traversal vulnerability is that an attacker can gain access to parts of the file system outside of the target folder in which they should reside. The attacker can then overwrite executable files and either invoke them remotely or wait for the system or user to call them, thus achieving Remote Command Execution on the victim's machine. The vulnerability can also cause damage by overwriting configuration files or other sensitive resources, and can be exploited on both client (user) machines and servers. https://snyk.io/research/zip-slip-vulnerability ### Specific Go Packages Affected helm.sh/helm/v3/pkg/plugin/installer ### Patches This issue has been fixed in Helm 3.2.4 ### For more information If you have any questions or comments about this advisory: * Open an issue in [the Helm repository](https://github.com/helm/helm/issues) * For security-specific issues, email us at [[email protected]](mailto:[email protected])

    Affected packages

    Package

    Name: helm.sh/helm/v3

    Purl: pkg:golang/helm.sh/helm/v3

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 3.0.0
    Fixed -3.2.4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-qq3j-xp49-j73f | CVE-DB