CRITICAL
In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd, or to execute a denial of service (DoS) via a special file such as /dev/urandom, via symlinks
Published Nov 12, 2019
9.8
CRITICALCVSS 3.1
EPSS 1.75%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.