Vulnerability Details CVE-2019-1010275
helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because self-signed client certs were aloowed. The component is: helm (many files updated, see https://github.com/helm/helm/pull/3152/files/1096813bf9a425e2aa4ac755b6c991b626dfab50). The attack vector is: A malicious client could connect to the server over the network. The fixed version is: 2.7.2.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.2%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2019-1010275
-
-
-
-
-
cpe:2.3:a:helm:helm:1.2.1
-
cpe:2.3:a:helm:helm:1.999.0
-
cpe:2.3:a:helm:helm:2.0.0
-
cpe:2.3:a:helm:helm:2.0.1
-
cpe:2.3:a:helm:helm:2.0.2
-
cpe:2.3:a:helm:helm:2.1.0
-
cpe:2.3:a:helm:helm:2.1.1
-
cpe:2.3:a:helm:helm:2.1.2
-
cpe:2.3:a:helm:helm:2.1.3
-
cpe:2.3:a:helm:helm:2.2.0
-
cpe:2.3:a:helm:helm:2.2.1
-
cpe:2.3:a:helm:helm:2.2.2
-
cpe:2.3:a:helm:helm:2.2.3
-
cpe:2.3:a:helm:helm:2.3.0
-
cpe:2.3:a:helm:helm:2.3.1
-
cpe:2.3:a:helm:helm:2.4.0
-
cpe:2.3:a:helm:helm:2.4.1
-
cpe:2.3:a:helm:helm:2.4.2
-
cpe:2.3:a:helm:helm:2.5.0
-
cpe:2.3:a:helm:helm:2.5.1
-
cpe:2.3:a:helm:helm:2.6.0
-
cpe:2.3:a:helm:helm:2.6.1
-
cpe:2.3:a:helm:helm:2.6.2
-
cpe:2.3:a:helm:helm:2.7.0
-
cpe:2.3:a:helm:helm:2.7.1