Path traversal in Helm - CVE-2024-25620
Published: February 15, 2024 / Updated: December 6, 2024
Vulnerability details
The vulnerability allows a remote user to overwrite arbitrary files on the system.
The vulnerability exists due to input validation error when processing directory traversal sequences when saving charts at Chart.yaml. A remote user can send a specially crafted HTTP request and overwrite arbitrary files on the system.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Package Hub 15
Containers Module
openSUSE Leap
SmartFabric Manager
IBM Cloud Transformation Advisor
Red Hat Advanced Cluster Management for Kubernetes
IBM Concert Software
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
helm-debuginfo
helm
helm-zsh-completion
helm-bash-completion
helm-fish-completion
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2024-25620
SmartFabric Manager - update to 1.2.0
IBM Cloud Transformation Advisor - update to 3.10.2
Red Hat Advanced Cluster Management for Kubernetes - update to 2.9.3
Red Hat OpenShift Container Platform - addressed in versions 4.15.3, 4.15.14, 4.17.0
IBM Concert Software - update to 1.0.1
Red Hat OpenShift GitOps - addressed in versions 1.11.6, 1.12.4
helm-debuginfo - update to 3.16.3-150000.1.38.1
helm - update to 3.16.3-150000.1.38.1
helm-zsh-completion - update to 3.16.3-150000.1.38.1
helm-bash-completion - update to 3.16.3-150000.1.38.1
helm-fish-completion - update to 3.16.3-150000.1.38.1
IBM Cloud Pak for Watson AIOps - update to 4.7.0
External References
Related Security Bulletins
- Path traversal in Helm
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.9
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.11
- Multiple vulnerabilities in IBM Concert
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- SUSE update for Recommended update for helm
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Dell SmartFabric Manager update for third-party components