Directory Traversal Affecting chartmuseum package, versions <0.16.1-r2


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.05% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Directory Traversal vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-CHAINGUARDLATEST-CHARTMUSEUM-6250154
  • published16 Feb 2024
  • disclosed15 Feb 2024

Introduced: 15 Feb 2024

CVE-2024-25620  (opens in a new tab)
CWE-22  (opens in a new tab)

How to fix?

Upgrade Chainguard chartmuseum to version 0.16.1-r2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream chartmuseum package and not the chartmuseum package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save a chart whose name within the Chart.yaml file includes a relative path change, the chart would be saved outside its expected directory based on the changes in the relative path. The validation and linting did not detect the path changes in the name. This issue has been resolved in Helm v3.14.1. Users unable to upgrade should check all charts used by Helm for path changes in their name as found in the Chart.yaml file. This includes dependencies.

CVSS Scores

version 3.1