Information disclosure in Helm - CVE-2021-32690
Published: June 17, 2021 / Updated: June 22, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the way Helm retrieves chart archives from external URLs. When a username and password are associated with a Helm repository, the
username and password are also passed on to other domains referenced in
the index.yaml file while retrieving a specific chart archive on the other domain.
Affected software
Arch Linux
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Web Terminal
IBM DB2
DB2 Warehouse on Cloud Pak for Data
How to mitigate CVE-2021-32690
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.3
Web Terminal - update to 1.3
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
IBM DB2 - update to 4.6
DB2 Warehouse on Cloud Pak for Data - update to 4.6
External References
Related Security Bulletins
- Credentials disclosure in Helm
- Arch Linux update for helm
- Multiple vulnerabilities in Red Hat Web Terminal
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.3
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67