Input validation error in Helm - CVE-2022-23525

 

Input validation error in Helm - CVE-2022-23525

Published: January 3, 2023


Vulnerability identifier: #VU70619
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23525
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the repo package when parsing a repository index file. A remote attacker can pass specially crafted repository index file to the application and perform a denial of service (DoS) attack.


Affected software

Helm
IBM Cloud Pak for Watson AIOps
ObjectScale
Dell EMC Streaming Data Platform
SUSE Linux Enterprise Server 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Containers
openSUSE Leap
Red Hat OpenShift Container Platform
SUSE Linux Enterprise Module for Packagehub Subpackages
helm3
helm
helm-debuginfo
helm-bash-completion
helm-fish-completion
helm-zsh-completion

How to mitigate CVE-2022-23525

Install update from vendor's website.

Helm - update to 3.10.3
ObjectScale - update to 1.3.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.11, 4.13.0
Dell EMC Streaming Data Platform - update to 1.7.0
helm3 - update to 3.3.3-150100.1.12.1
helm - update to 3.10.3-150000.1.13.1
helm-debuginfo - update to 3.10.3-150000.1.13.1
helm-bash-completion - update to 3.10.3-150000.1.13.1
helm-fish-completion - update to 3.10.3-150000.1.13.1
helm-zsh-completion - update to 3.10.3-150000.1.13.1

External References

Related Security Bulletins