Path Traversal Affecting github.com/helm/helm/pkg/chartutil package, versions <3.14.1
Threat Intelligence
EPSS
0.04% (12th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMHELMHELMPKGCHARTUTIL-6247642
- published 15 Feb 2024
- disclosed 15 Feb 2024
- credit Dominykas Blyžė
Introduced: 15 Feb 2024
CVE-2024-25620 Open this link in a new tabHow to fix?
Upgrade github.com/helm/helm/pkg/chartutil
to version 3.14.1 or higher.
Overview
github.com/helm/helm/pkg/chartutil is a package manager for kubernetes.
Affected versions of this package are vulnerable to Path Traversal when handling chart archive paths used as filenames in Chart.yaml
. An attacker can save a file outside its expected directory based on the changes in the relative path.
References
CVSS Scores
version 3.1