CVE-2020-4053
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
16/06/2020
Last modified:
08/02/2024
Description
In Helm greater than or equal to 3.0.0 and less than 3.2.4, a path traversal attack is possible when installing Helm plugins from a tar archive over HTTP. It is possible for a malicious plugin author to inject a relative path into a plugin archive, and copy a file outside of the intended directory. This has been fixed in 3.2.4.
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM
Base Score 2.0
8.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:* | 3.0.0 (including) | 3.2.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



