Code injection in Helm - CVE-2021-21303

 

Code injection in Helm - CVE-2021-21303

Published: February 5, 2021 / Updated: February 9, 2021


Vulnerability identifier: #VU50431
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21303
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient sanitization of user-supplied data passed via various files in index.yaml, plugin.yaml, and Chart.yaml files and via a SemVer in the version field. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the system.


Affected software

Helm
Arch Linux
IBM DB2
DB2 Warehouse on Cloud Pak for Data

How to mitigate CVE-2021-21303

Install updates from vendor's website.

Helm - update to 3.5.2
IBM DB2 - update to 4.6
DB2 Warehouse on Cloud Pak for Data - update to 4.6

External References

Related Security Bulletins