NULL Pointer Dereference Affecting github.com/helm/helm/pkg/repo package, versions <3.10.3


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.09% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about NULL Pointer Dereference vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMHELMHELMPKGREPO-3172917
  • published15 Dec 2022
  • disclosed14 Dec 2022
  • creditAdamKorcz, DavidKorczynski

Introduced: 14 Dec 2022

CVE-2022-23525  (opens in a new tab)
CWE-476  (opens in a new tab)

How to fix?

Upgrade github.com/helm/helm/pkg/repo to version 3.10.3 or higher.

Overview

github.com/helm/helm/pkg/repo is a package manager for kubernetes.

Affected versions of this package are vulnerable to NULL Pointer Dereference due to accepting input to functions which can cause a segmentation violation. The Helm Client will panic with an index file that causes a memory violation panic.

Workaround

SDK users can validate index files that are correctly formatted before passing them to the repo functions.

CVSS Scores

version 3.1