Input validation error in Helm - CVE-2022-23526

 

Input validation error in Helm - CVE-2022-23526

Published: January 3, 2023


Vulnerability identifier: #VU70618
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23526
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the chartutil package. A remote attacker can pass specially crafted JSON Schema validation file to the application and perform a denial of service (DoS) attack.


Affected software

Helm
IBM Cloud Pak for Watson AIOps
ObjectScale
Dell EMC Streaming Data Platform
SUSE Linux Enterprise Server 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Fedora
Red Hat OpenShift Container Platform
SUSE Linux Enterprise Module for Packagehub Subpackages
golang-github-need-being-tree-0.1.0-1.fc36 golang-helm-3-3.11.1-2.fc36 golang-oras-0.15.1-1.20221105git690716b.fc36 golang-oras-1-1.2.1-1.fc36 golang-oras-2
golang-github-need-being-tree-0.1.0-1.fc37 golang-helm-3-3.11.1-1.fc37 golang-oras-0.15.1-1.20221105git690716b.fc37 golang-oras-1-1.2.1-1.fc37 golang-oras-2
golang-github-need-being-tree-0.1.0-1.fc38 golang-helm-3-3.11.1-1.fc38 golang-oras-0.15.1-1.20221105git690716b.fc38 golang-oras-1-1.2.1-1.fc38 golang-oras-2
helm3
helm
helm-debuginfo
helm-bash-completion
helm-fish-completion
helm-zsh-completion
golang-helm-3

How to mitigate CVE-2022-23526

Install update from vendor's website.

Helm - update to 3.10.3
ObjectScale - update to 1.3.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.11, 4.13.0
Dell EMC Streaming Data Platform - update to 1.7.0
golang-github-need-being-tree-0.1.0-1.fc36 golang-helm-3-3.11.1-2.fc36 golang-oras-0.15.1-1.20221105git690716b.fc36 golang-oras-1-1.2.1-1.fc36 golang-oras-2 - update to 2.0.0~rc.4-1.fc36
golang-github-need-being-tree-0.1.0-1.fc37 golang-helm-3-3.11.1-1.fc37 golang-oras-0.15.1-1.20221105git690716b.fc37 golang-oras-1-1.2.1-1.fc37 golang-oras-2 - update to 2.0.0~rc.4-1.fc37
golang-github-need-being-tree-0.1.0-1.fc38 golang-helm-3-3.11.1-1.fc38 golang-oras-0.15.1-1.20221105git690716b.fc38 golang-oras-1-1.2.1-1.fc38 golang-oras-2 - update to 2.0.0~rc.4-1.fc38
helm3 - update to 3.3.3-150100.1.15.1
helm - update to 3.10.3-150000.1.13.1
helm-debuginfo - update to 3.10.3-150000.1.13.1
helm-bash-completion - update to 3.10.3-150000.1.13.1
helm-fish-completion - update to 3.10.3-150000.1.13.1
helm-zsh-completion - update to 3.10.3-150000.1.13.1
golang-helm-3 - update to 3.11.1-1.fc39

External References

Related Security Bulletins