Improper Certificate Validation in Helm Affects Multiple Versions
CVE-2019-1010275
9.8CRITICAL
What is CVE-2019-1010275?
Helm versions prior to 2.7.2 are susceptible to a vulnerability that allows unauthorized clients to connect to the server due to improper validation of self-signed client certificates. This oversight can be exploited by a malicious client remotely, gaining unintended access and control. To mitigate this risk, users should upgrade to version 2.7.2 or later, as this release addresses the certificate validation issues. For detailed insights and updates, refer to the official Helm documentation and the associated GitHub repository.
Affected Version(s)
helm Before 2.7.2 [fixed: 2.7.2]
