Information disclosure in Helm - CVE-2021-32690

 

Information disclosure in Helm - CVE-2021-32690

Published: June 17, 2021 / Updated: June 22, 2021


Vulnerability identifier: #VU54184
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32690
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to the way Helm retrieves chart archives from external URLs. When a username and password are associated with a Helm repository, the username and password are also passed on to other domains referenced in the index.yaml file while retrieving a specific chart archive on the other domain.


Affected software

Helm
Arch Linux
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Web Terminal
IBM DB2
DB2 Warehouse on Cloud Pak for Data

How to mitigate CVE-2021-32690

Install updates from vendor's website.

Helm - update to 3.6.1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.3
Web Terminal - update to 1.3
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
IBM DB2 - update to 4.6
DB2 Warehouse on Cloud Pak for Data - update to 4.6

External References

Related Security Bulletins