CVE-2019-1000008
Last modified
CVE-2019-1000008 is a vulnerability of currently unknown severity. All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The commands `helm fetch --untar` and `helm lint some.tgz` that can result when chart archive files are unpacked a file may be unpacked outside of the target directory. This attack appears to be exploitable via a victim must run a helm command on a specially crafted chart archive. EPSS estimates a 1.48% chance of exploitation in the next 30 days.
Description
All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The commands `helm fetch --untar` and `helm lint some.tgz` that can result when chart archive files are unpacked a file may be unpacked outside of the target directory. This attack appears to be exploitable via a victim must run a helm command on a specially crafted chart archive. This vulnerability appears to have been fixed in 2.12.2.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Helm | Helm | >= 2.0.0, < 2.12.2 |
References
- https://helm.sh/blog/helm-security-notice-2019/index.htmlExploit, Mitigation, Vendor Advisory
- https://helm.sh/blog/helm-security-notice-2019/index.htmlExploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1000008?
How severe is CVE-2019-1000008?
How do I fix CVE-2019-1000008?
Are you affected by CVE-2019-1000008?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
