Back

CRITICAL

helm: shows secrets with --dry-run option in clear text

Published Mar 3, 2024

Description

An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor's position is that this behavior was introduced intentionally, and cannot be removed without breaking backwards compatibility (some users may be relying on these values). Also, it is not the Helm Project's responsibility if a user decides to use --dry-run within a CI/CD environment whose output is visible to unauthorized persons.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 3, 2024
Updated Sep 4, 2024
Reserved Mar 3, 2024
CISA Vulnrichment
Updated Aug 19, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 3, 2024
ENISA EUVD
Assigner mitre
Published Mar 3, 2024
Updated Sep 4, 2024
Exploited since n/a
EUVD-2024-0953