GO-2022-1040
Dashboard / Vulnerabilities / GO-2022-1040
GO-2022-1040
Published: 18 Oct 2022Last Modified: 20 May 2024
Summary: Insufficient sanitization of data files in helm.sh/helm/v3
Details: Helm does not sanitize all fields read from repository data files. A maliciously crafted data file may contain strings containing arbitrary data. If printed to a terminal, a malicious string could obscure or alter data on the screen.
References: https://github.com/advisories/GHSA-c38g-469g-cmgx, https://github.com/helm/helm/commit/6ce9ba60b73013857e2e7c73d3f86ed70bc1ac9a
Affected packages
Package
Name: helm.sh/helm/v3
Purl: pkg:golang/helm.sh/helm/v3
Affected ranges
Type: SEMVER
Events:
Introduced- 3.0.0
Fixed -3.5.2
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
