Information Exposure Affecting servicemesh-galley package, versions *


Severity

Recommended
0.0
medium
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.15% (52nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL8-SERVICEMESHGALLEY-4401454
  • published26 Mar 2023
  • disclosed16 Jun 2021

Introduced: 16 Jun 2021

CVE-2021-32690  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:8 servicemesh-galley.

NVD Description

Note: Versions mentioned in the description apply only to the upstream servicemesh-galley package and not the servicemesh-galley package as distributed by RHEL. See How to fix? for RHEL:8 relevant fixed versions and status.

Helm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists where the username and password credentials associated with a Helm repository could be passed on to another domain referenced by that Helm repository. This issue has been resolved in 3.6.1. There is a workaround through which one may check for improperly passed credentials. One may use a username and password for a Helm repository and may audit the Helm repository in order to check for another domain being used that could have received the credentials. In the index.yaml file for that repository, one may look for another domain in the urls list for the chart versions. If there is another domain found and that chart version was pulled or installed, the credentials would be passed on.

CVSS Scores

version 3.1