Link following in Helm - CVE-2019-18658

 

Link following in Helm - CVE-2019-18658

Published: November 12, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30626
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-18658
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd, or to execute a denial of service (DoS) via a special file such as /dev/urandom, via symlinks. No version of Tiller is known to be impacted. This is a client-only issue.


Affected software

Helm
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
openSUSE Leap
helm-mirror
helm-mirror-debuginfo

How to mitigate CVE-2019-18658

Install update from vendor's website.

Helm - update to 2.15.2
helm-mirror - update to 0.3.1-150000.1.13.1
helm-mirror-debuginfo - update to 0.3.1-150000.1.13.1

External References

Related Security Bulletins