Symlink Attack Affecting helm.sh/helm/v3/pkg/chartutil package, versions >=2.0.0 <2.15.2


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.22% (62nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-HELMSHHELMV3PKGCHARTUTIL-5777897
  • published18 Jul 2023
  • disclosed24 May 2022
  • creditMatt Farina

Introduced: 24 May 2022

CVE-2019-18658  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

Upgrade helm.sh/helm/v3/pkg/chartutil to version 2.15.2 or higher.

Overview

helm.sh/helm/v3/pkg/chartutil is a package manager for kubernetes.

Affected versions of this package are vulnerable to Symlink Attack by using a maliciously designed chart to include sensitive content, such as /etc/passwd, or to execute a denial of service (DoS) by a special file, such as /dev/urandom, via symlinks.

Note: This is a client-only issue.

Workaround

Do not load chart directories or package charts whose contents you do not trust or in an environment with sensitive information.

CVSS Scores

version 3.1