Use of Uninitialized Resource Affecting helm.sh/helm/v3/pkg/repo package, versions <3.14.2


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-HELMSHHELMV3PKGREPO-6261791
  • published23 Feb 2024
  • disclosed22 Feb 2024
  • creditJakub Ciolek

Introduced: 22 Feb 2024

CVE-2024-26147  (opens in a new tab)
CWE-457  (opens in a new tab)

How to fix?

Upgrade helm.sh/helm/v3/pkg/repo to version 3.14.2 or higher.

Overview

helm.sh/helm/v3/pkg/repo is a package manager for kubernetes.

Affected versions of this package are vulnerable to Use of Uninitialized Resource when using the LoadIndexFile or DownloadIndexFile functions in the repo package, or the LoadDir function in the plugin package. When a malicious plugin with no metadata is added, Helm inspects all known plugins on each invocation, causing the client to panic. If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem.

Details

Denial of Service (DoS) describes a family of attacks, all aimed at making a system inaccessible to its intended and legitimate users.

Unlike other vulnerabilities, DoS attacks usually do not aim at breaching security. Rather, they are focused on making websites and services unavailable to genuine users resulting in downtime.

One popular Denial of Service vulnerability is DDoS (a Distributed Denial of Service), an attack that attempts to clog network pipes to the system by generating a large volume of traffic from many machines.

When it comes to open source libraries, DoS vulnerabilities allow attackers to trigger such a crash or crippling of the service by using a flaw either in the application code or from the use of open source libraries.

Two common types of DoS vulnerabilities:

  • High CPU/Memory Consumption- An attacker sending crafted requests that could cause the system to take a disproportionate amount of time to process. For example, commons-fileupload:commons-fileupload.

  • Crash - An attacker sending crafted requests that could cause the system to crash. For Example, npm ws package

CVSS Scores

version 3.1