#VU86548 Path traversal in Helm - CVE-2024-25620
Published: February 15, 2024 / Updated: December 6, 2024
Helm
The Helm Project
Description
The vulnerability allows a remote user to overwrite arbitrary files on the system.
The vulnerability exists due to input validation error when processing directory traversal sequences when saving charts at Chart.yaml. A remote user can send a specially crafted HTTP request and overwrite arbitrary files on the system.