In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd, or to execute a denial of service (DoS) via a special file such as /dev/urandom, via symlinks. No version of Tiller is known to be impacted. This is a client-only issue.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-59"
],
"github_reviewed_at": "2023-07-17T23:57:06Z",
"nvd_published_at": "2019-11-12T14:15:00Z",
"severity": "CRITICAL"
}