helm.sh/helm
Go7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting helm.sh/helmpage 1 of 1
- CVE-2019-1000008MEDIUMCVSS 6.5✓ Fixed in 2.12.2+incompatible2019-02-04
All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The commands `helm fetch --untar` and `helm lint some.tgz` that can r…
- CVE-2019-1010275CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.7.2+incompatible2019-07-17
helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because self-signed client certs were aloowed. The component is: helm (many files updated, see http…
- CVE-2019-18658CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.15.2+incompatible2019-11-12
In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd, or to execute a denial of serv…
- CVE-2020-15184LOWCVSS 3.7EG 3.7✓ Fixed in 2.16.112020-09-17
In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3…
- CVE-2020-15185LOWCVSS 2.2EG 2.2✓ Fixed in 2.16.112020-09-17
In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad ch…
- CVE-2020-15186LOWCVSS 3.4EG 3.4✓ Fixed in 2.16.112020-09-17
In Helm before versions 2.16.11 and 3.3.2 plugin names are not sanitized properly. As a result, a malicious plugin author could use characters in a plugin name that would result in unexpected behavior, such as duplicating the name of anoth…
- CVE-2020-15187LOWCVSS 3.0EG 3.0✓ Fixed in 2.16.112020-09-17
In Helm before versions 2.16.11 and 3.3.2, a Helm plugin can contain duplicates of the same entry, with the last one always used. If a plugin is compromised, this lowers the level of access that an attacker needs to modify a plugin's insta…
Check whether helm.sh/helm is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for helm.sh/helm CVEs against the assets you own.
Start Free Scan →