Input validation error in Helm - CVE-2022-23526
Published: January 3, 2023
Vulnerability identifier: #VU70618
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23526
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the chartutil package. A remote attacker can pass specially crafted JSON Schema validation file to the application and perform a denial of service (DoS) attack.
Affected software
Helm
IBM Cloud Pak for Watson AIOps
ObjectScale
Dell EMC Streaming Data Platform
SUSE Linux Enterprise Server 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Fedora
Red Hat OpenShift Container Platform
SUSE Linux Enterprise Module for Packagehub Subpackages
golang-github-need-being-tree-0.1.0-1.fc36 golang-helm-3-3.11.1-2.fc36 golang-oras-0.15.1-1.20221105git690716b.fc36 golang-oras-1-1.2.1-1.fc36 golang-oras-2
golang-github-need-being-tree-0.1.0-1.fc37 golang-helm-3-3.11.1-1.fc37 golang-oras-0.15.1-1.20221105git690716b.fc37 golang-oras-1-1.2.1-1.fc37 golang-oras-2
golang-github-need-being-tree-0.1.0-1.fc38 golang-helm-3-3.11.1-1.fc38 golang-oras-0.15.1-1.20221105git690716b.fc38 golang-oras-1-1.2.1-1.fc38 golang-oras-2
helm3
helm
helm-debuginfo
helm-bash-completion
helm-fish-completion
helm-zsh-completion
golang-helm-3
IBM Cloud Pak for Watson AIOps
ObjectScale
Dell EMC Streaming Data Platform
SUSE Linux Enterprise Server 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Fedora
Red Hat OpenShift Container Platform
SUSE Linux Enterprise Module for Packagehub Subpackages
golang-github-need-being-tree-0.1.0-1.fc36 golang-helm-3-3.11.1-2.fc36 golang-oras-0.15.1-1.20221105git690716b.fc36 golang-oras-1-1.2.1-1.fc36 golang-oras-2
golang-github-need-being-tree-0.1.0-1.fc37 golang-helm-3-3.11.1-1.fc37 golang-oras-0.15.1-1.20221105git690716b.fc37 golang-oras-1-1.2.1-1.fc37 golang-oras-2
golang-github-need-being-tree-0.1.0-1.fc38 golang-helm-3-3.11.1-1.fc38 golang-oras-0.15.1-1.20221105git690716b.fc38 golang-oras-1-1.2.1-1.fc38 golang-oras-2
helm3
helm
helm-debuginfo
helm-bash-completion
helm-fish-completion
helm-zsh-completion
golang-helm-3
How to mitigate CVE-2022-23526
Install update from vendor's website.
Helm - update to 3.10.3
ObjectScale - update to 1.3.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.11, 4.13.0
Dell EMC Streaming Data Platform - update to 1.7.0
golang-github-need-being-tree-0.1.0-1.fc36 golang-helm-3-3.11.1-2.fc36 golang-oras-0.15.1-1.20221105git690716b.fc36 golang-oras-1-1.2.1-1.fc36 golang-oras-2 - update to 2.0.0~rc.4-1.fc36
golang-github-need-being-tree-0.1.0-1.fc37 golang-helm-3-3.11.1-1.fc37 golang-oras-0.15.1-1.20221105git690716b.fc37 golang-oras-1-1.2.1-1.fc37 golang-oras-2 - update to 2.0.0~rc.4-1.fc37
golang-github-need-being-tree-0.1.0-1.fc38 golang-helm-3-3.11.1-1.fc38 golang-oras-0.15.1-1.20221105git690716b.fc38 golang-oras-1-1.2.1-1.fc38 golang-oras-2 - update to 2.0.0~rc.4-1.fc38
helm3 - update to 3.3.3-150100.1.15.1
helm - update to 3.10.3-150000.1.13.1
helm-debuginfo - update to 3.10.3-150000.1.13.1
helm-bash-completion - update to 3.10.3-150000.1.13.1
helm-fish-completion - update to 3.10.3-150000.1.13.1
helm-zsh-completion - update to 3.10.3-150000.1.13.1
golang-helm-3 - update to 3.11.1-1.fc39
ObjectScale - update to 1.3.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.11, 4.13.0
Dell EMC Streaming Data Platform - update to 1.7.0
golang-github-need-being-tree-0.1.0-1.fc36 golang-helm-3-3.11.1-2.fc36 golang-oras-0.15.1-1.20221105git690716b.fc36 golang-oras-1-1.2.1-1.fc36 golang-oras-2 - update to 2.0.0~rc.4-1.fc36
golang-github-need-being-tree-0.1.0-1.fc37 golang-helm-3-3.11.1-1.fc37 golang-oras-0.15.1-1.20221105git690716b.fc37 golang-oras-1-1.2.1-1.fc37 golang-oras-2 - update to 2.0.0~rc.4-1.fc37
golang-github-need-being-tree-0.1.0-1.fc38 golang-helm-3-3.11.1-1.fc38 golang-oras-0.15.1-1.20221105git690716b.fc38 golang-oras-1-1.2.1-1.fc38 golang-oras-2 - update to 2.0.0~rc.4-1.fc38
helm3 - update to 3.3.3-150100.1.15.1
helm - update to 3.10.3-150000.1.13.1
helm-debuginfo - update to 3.10.3-150000.1.13.1
helm-bash-completion - update to 3.10.3-150000.1.13.1
helm-fish-completion - update to 3.10.3-150000.1.13.1
helm-zsh-completion - update to 3.10.3-150000.1.13.1
golang-helm-3 - update to 3.11.1-1.fc39
External References
Related Security Bulletins
- Multiple vulnerabilities in Helm
- SUSE update for helm
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Dell Streaming Data Platform
- Fedora 39 update for golang-helm-3
- Fedora 38 update for golang-github-need-being-tree-0.1.0-1.fc38 golang-helm-3-3.11.1-1.fc38 golang-oras-0.15.1-1.20221105git690716b.fc38 golang-oras-1-1.2.1-1.fc38 golang-oras-2
- Fedora 37 update for golang-github-need-being-tree-0.1.0-1.fc37 golang-helm-3-3.11.1-1.fc37 golang-oras-0.15.1-1.20221105git690716b.fc37 golang-oras-1-1.2.1-1.fc37 golang-oras-2
- Fedora 36 update for golang-github-need-being-tree-0.1.0-1.fc36 golang-helm-3-3.11.1-2.fc36 golang-oras-0.15.1-1.20221105git690716b.fc36 golang-oras-1-1.2.1-1.fc36 golang-oras-2
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- SUSE update for helm3
- Multiple vulnerabilities in Dell ObjectScale