#VU54184 Information disclosure in Helm - CVE-2021-32690
Published: June 17, 2021 / Updated: June 22, 2021
Helm
The Helm Project
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the way Helm retrieves chart archives from external URLs. When a username and password are associated with a Helm repository, the
username and password are also passed on to other domains referenced in
the index.yaml file while retrieving a specific chart archive on the other domain.