CVE-2019-1000009

Source
https://cve.org/CVERecord?id=CVE-2019-1000009
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-1000009.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-1000009
Published
2019-02-04T21:29:00.957Z
Modified
2026-04-10T04:13:52.077751Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Helm ChartMuseum version >=0.1.0 and < 0.8.1 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HTTP API to save charts that can result in a specially crafted chart could be uploaded and saved outside the intended location. This attack appears to be exploitable via A POST request to the HTTP API can save a chart archive outside of the intended directory. If authentication is, optionally, enabled this requires an authorized user to do so. This vulnerability appears to have been fixed in 0.8.1.

References

Affected packages

Git / github.com/helm/chartmuseum

Affected ranges

Type
GIT
Repo
https://github.com/helm/chartmuseum
Events
Database specific
{
    "versions": [
        {
            "introduced": "0.1.0"
        },
        {
            "fixed": "0.8.1"
        }
    ]
}

Affected versions

v0.*
v0.1.0
v0.1.1
v0.1.2
v0.2.0
v0.2.1
v0.2.2
v0.2.3
v0.2.4
v0.2.5
v0.2.6
v0.2.7
v0.2.8
v0.3.0
v0.3.1
v0.4.0
v0.4.1
v0.4.2
v0.5.0
v0.5.1
v0.6.0
v0.7.0
v0.7.1
v0.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-1000009.json"