CVE-2020-15185
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/09/2020
Last modified:
05/08/2022
Description
In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad chart into a repository. To perform this attack, an attacker must have write access to the index file (which can occur during a MITM attack on a non-SSL connection). This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the index file in the Helm repository cache before installing software.
Impact
Base Score 3.x
2.70
Severity 3.x
LOW
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:* | 2.0.0 (including) | 2.16.11 (excluding) |
| cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:* | 3.0.0 (including) | 3.3.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



