Information disclosure in Helm - CVE-2023-25165

 

Information disclosure in Helm - CVE-2023-25165

Published: February 8, 2023 / Updated: March 11, 2023


Vulnerability identifier: #VU72073
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25165
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to insecure usage of the getHostByName template function. A remote attacker can use DNS exfiltration technique to gain access to sensitive information.


Affected software

Helm
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
ObjectScale
Dell EMC Streaming Data Platform
IBM Cloud Pak for Watson AIOps
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
Public Cloud Module
Containers Module
SUSE Package Hub 15
openSUSE Leap
Red Hat OpenShift Container Platform
terraform-provider-helm
helm-debuginfo
helm
helm-bash-completion
helm-fish-completion
helm-zsh-completion

How to mitigate CVE-2023-25165

Install updates from vendor's website.

Helm - update to 3.11.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.53, 4.13.0
ObjectScale - update to 1.4.0
Dell EMC Streaming Data Platform - update to 1.7.0
terraform-provider-helm - addressed in versions 2.9.0-150100.3.6.3, 2.9.0-150200.6.8.1
helm-debuginfo - update to 3.11.1-150000.1.16.1
helm - update to 3.11.1-150000.1.16.1
helm-bash-completion - update to 3.11.1-150000.1.16.1
helm-fish-completion - update to 3.11.1-150000.1.16.1
helm-zsh-completion - update to 3.11.1-150000.1.16.1
IBM Cloud Pak for Watson AIOps - update to 4.1

External References

Related Security Bulletins