Input validation error in Helm - CVE-2022-23524

 

Input validation error in Helm - CVE-2022-23524

Published: January 3, 2023


Vulnerability identifier: #VU70620
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23524
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the strvals package when parsing string values. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Helm
IBM Cloud Pak for Watson AIOps
ObjectScale
Dell EMC Streaming Data Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Containers
openSUSE Leap
Fedora
Red Hat OpenShift Container Platform
SUSE Linux Enterprise Module for Packagehub Subpackages
golang-github-need-being-tree-0.1.0-1.fc36 golang-helm-3-3.11.1-2.fc36 golang-oras-0.15.1-1.20221105git690716b.fc36 golang-oras-1-1.2.1-1.fc36 golang-oras-2
golang-github-need-being-tree-0.1.0-1.fc37 golang-helm-3-3.11.1-1.fc37 golang-oras-0.15.1-1.20221105git690716b.fc37 golang-oras-1-1.2.1-1.fc37 golang-oras-2
golang-github-need-being-tree-0.1.0-1.fc38 golang-helm-3-3.11.1-1.fc38 golang-oras-0.15.1-1.20221105git690716b.fc38 golang-oras-1-1.2.1-1.fc38 golang-oras-2
helm
helm-debuginfo
helm-bash-completion
helm-fish-completion
helm-zsh-completion
golang-helm-3

How to mitigate CVE-2022-23524

Install updates from vendor's website.

Helm - update to 3.10.3
ObjectScale - update to 1.3.0
Red Hat OpenShift Container Platform - update to 4.12.11
Dell EMC Streaming Data Platform - update to 1.7.0
golang-github-need-being-tree-0.1.0-1.fc36 golang-helm-3-3.11.1-2.fc36 golang-oras-0.15.1-1.20221105git690716b.fc36 golang-oras-1-1.2.1-1.fc36 golang-oras-2 - update to 2.0.0~rc.4-1.fc36
golang-github-need-being-tree-0.1.0-1.fc37 golang-helm-3-3.11.1-1.fc37 golang-oras-0.15.1-1.20221105git690716b.fc37 golang-oras-1-1.2.1-1.fc37 golang-oras-2 - update to 2.0.0~rc.4-1.fc37
golang-github-need-being-tree-0.1.0-1.fc38 golang-helm-3-3.11.1-1.fc38 golang-oras-0.15.1-1.20221105git690716b.fc38 golang-oras-1-1.2.1-1.fc38 golang-oras-2 - update to 2.0.0~rc.4-1.fc38
helm - update to 3.10.3-150000.1.13.1
helm-debuginfo - update to 3.10.3-150000.1.13.1
helm-bash-completion - update to 3.10.3-150000.1.13.1
helm-fish-completion - update to 3.10.3-150000.1.13.1
helm-zsh-completion - update to 3.10.3-150000.1.13.1
golang-helm-3 - update to 3.11.1-1.fc39

External References

Related Security Bulletins