Skip to content

Aliases are never checked

Low
technosophos published GHSA-9vp5-m38w-j776 Sep 17, 2020

Package

No package listed

Affected versions

2.0.0-2.16.10, 3.0.0-3.3.1

Patched versions

3.3.2, 2.16.11

Description

Impact

During a security audit of Helm's code base, security researchers at Trail of Bits identified a bug in which the alias field on a Chart.yaml is not properly sanitized. This could lead to the injection of unwanted information into a chart.

Patches

This issue has been patched in Helm 3.3.2 and 2.16.11

Workarounds

Manually review the dependencies field of any untrusted chart, verifying that the alias field is either not used, or (if used) does not contain newlines or path characters.

Severity

Low

CVE ID

CVE-2020-15184

Weaknesses

No CWEs