Information Exposure Affecting terraform-provider-helm package, versions <2.9.0-150200.6.8.1


Severity

Recommended
0.0
medium
0
10

Based on SUSE Linux Enterprise Server security rating.

Threat Intelligence

EPSS
0.76% (51st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-SLES154-TERRAFORMPROVIDERHELM-5411422
  • published5 Apr 2023
  • disclosed4 Apr 2023

Introduced: 4 Apr 2023

CVE-2023-25165  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade SLES:15.4 terraform-provider-helm to version 2.9.0-150200.6.8.1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream terraform-provider-helm package and not the terraform-provider-helm package as distributed by SLES. See How to fix? for SLES:15.4 relevant fixed versions and status.

Helm is a tool that streamlines installing and managing Kubernetes applications.getHostByName is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with helm install|upgrade|template or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject getHostByName into a chart in order to disclose values to a malicious DNS server. The issue has been fixed in Helm 3.11.1. Prior to using a chart with Helm verify the getHostByName function is not being used in a template to disclose any information you do not want passed to DNS servers.

CVSS Base Scores

version 3.1