Vulnerability Description
All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The commands `helm fetch --untar` and `helm lint some.tgz` that can result when chart archive files are unpacked a file may be unpacked outside of the target directory. This attack appears to be exploitable via a victim must run a helm command on a specially crafted chart archive. This vulnerability appears to have been fixed in 2.12.2.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Helm | Helm | >= 2.0.0, < 2.12.2 |
Related Weaknesses (CWE)
References
- https://helm.sh/blog/helm-security-notice-2019/index.htmlExploitMitigationVendor Advisory
- https://helm.sh/blog/helm-security-notice-2019/index.htmlExploitMitigationVendor Advisory
FAQ
What is CVE-2019-1000008?
CVE-2019-1000008 is a vulnerability with a CVSS score of 6.5 (MEDIUM). All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The commands `helm fetch --unt...
How severe is CVE-2019-1000008?
CVE-2019-1000008 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1000008?
Check the references section above for vendor advisories and patch information. Affected products include: Helm Helm.