Information disclosure in Helm - CVE-2023-25165
Published: February 8, 2023 / Updated: March 11, 2023
Vulnerability identifier: #VU72073
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25165
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to insecure usage of the getHostByName template function. A remote attacker can use DNS exfiltration technique to gain access to sensitive information.
Affected software
Helm
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
ObjectScale
Dell EMC Streaming Data Platform
IBM Cloud Pak for Watson AIOps
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
Public Cloud Module
Containers Module
SUSE Package Hub 15
openSUSE Leap
Red Hat OpenShift Container Platform
terraform-provider-helm
helm-debuginfo
helm
helm-bash-completion
helm-fish-completion
helm-zsh-completion
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
ObjectScale
Dell EMC Streaming Data Platform
IBM Cloud Pak for Watson AIOps
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
Public Cloud Module
Containers Module
SUSE Package Hub 15
openSUSE Leap
Red Hat OpenShift Container Platform
terraform-provider-helm
helm-debuginfo
helm
helm-bash-completion
helm-fish-completion
helm-zsh-completion
How to mitigate CVE-2023-25165
Install updates from vendor's website.
Helm - update to 3.11.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.53, 4.13.0
ObjectScale - update to 1.4.0
Dell EMC Streaming Data Platform - update to 1.7.0
terraform-provider-helm - addressed in versions 2.9.0-150100.3.6.3, 2.9.0-150200.6.8.1
helm-debuginfo - update to 3.11.1-150000.1.16.1
helm - update to 3.11.1-150000.1.16.1
helm-bash-completion - update to 3.11.1-150000.1.16.1
helm-fish-completion - update to 3.11.1-150000.1.16.1
helm-zsh-completion - update to 3.11.1-150000.1.16.1
IBM Cloud Pak for Watson AIOps - update to 4.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.53, 4.13.0
ObjectScale - update to 1.4.0
Dell EMC Streaming Data Platform - update to 1.7.0
terraform-provider-helm - addressed in versions 2.9.0-150100.3.6.3, 2.9.0-150200.6.8.1
helm-debuginfo - update to 3.11.1-150000.1.16.1
helm - update to 3.11.1-150000.1.16.1
helm-bash-completion - update to 3.11.1-150000.1.16.1
helm-fish-completion - update to 3.11.1-150000.1.16.1
helm-zsh-completion - update to 3.11.1-150000.1.16.1
IBM Cloud Pak for Watson AIOps - update to 4.1
External References
Related Security Bulletins
- Information disclosure in Helm
- SUSE update for helm
- SUSE update for terraform-provider-helm
- SUSE update for terraform-provider-helm
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in Dell Streaming Data Platform
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Dell ObjectScale