In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd
, or to execute a denial of service (DoS) via a special file such as /dev/urandom, via symlinks. No version of Tiller is known to be impacted. This is a client-only issue.
{ "nvd_published_at": "2019-11-12T14:15:00Z", "cwe_ids": [ "CWE-59" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2023-07-17T23:57:06Z" }