Path Traversal Vulnerability in Helm by Deis, Inc.
CVE-2019-1000008

6.5MEDIUM

Key Information:

Vendor

Helm

Status
Vendor
CVE Published:
4 February 2019

What is CVE-2019-1000008?

All versions of Helm from 2.0.0 up to but not including 2.12.2 are susceptible to a path traversal vulnerability. This issue arises from improper handling of file paths during the execution of specific commands like helm fetch --untar and helm lint some.tgz. An attacker can exploit this vulnerability by tricking a user into running Helm commands on a maliciously crafted chart archive, allowing files to be extracted to unintended locations outside the designated directory. Users are advised to upgrade to version 2.12.2 or later to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.