Code injection in Helm - CVE-2021-21303
Published: February 5, 2021 / Updated: February 9, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via various files in index.yaml, plugin.yaml, and Chart.yaml files and via a SemVer in the version field. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the system.
Affected software
Arch Linux
IBM DB2
DB2 Warehouse on Cloud Pak for Data
How to mitigate CVE-2021-21303
IBM DB2 - update to 4.6
DB2 Warehouse on Cloud Pak for Data - update to 4.6