Vulnerability Details CVE-2020-15184
In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the `dependencies` field of any untrusted chart, verifying that the `alias` field is either not used, or (if used) does not contain newlines or path characters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.2%
CVSS Severity
CVSS v3 Score 3.7
CVSS v2 Score 4.0
Products affected by CVE-2020-15184
-
cpe:2.3:a:helm:helm:2.0.0
-
cpe:2.3:a:helm:helm:2.0.1
-
cpe:2.3:a:helm:helm:2.0.2
-
cpe:2.3:a:helm:helm:2.1.0
-
cpe:2.3:a:helm:helm:2.1.1
-
cpe:2.3:a:helm:helm:2.1.2
-
cpe:2.3:a:helm:helm:2.1.3
-
cpe:2.3:a:helm:helm:2.10.0
-
cpe:2.3:a:helm:helm:2.11.0
-
cpe:2.3:a:helm:helm:2.12.0
-
cpe:2.3:a:helm:helm:2.12.1
-
cpe:2.3:a:helm:helm:2.12.2
-
cpe:2.3:a:helm:helm:2.12.3
-
cpe:2.3:a:helm:helm:2.13.0
-
cpe:2.3:a:helm:helm:2.13.1
-
cpe:2.3:a:helm:helm:2.14.0
-
cpe:2.3:a:helm:helm:2.14.1
-
cpe:2.3:a:helm:helm:2.14.2
-
cpe:2.3:a:helm:helm:2.14.3
-
cpe:2.3:a:helm:helm:2.15.0
-
cpe:2.3:a:helm:helm:2.15.1
-
cpe:2.3:a:helm:helm:2.15.2
-
cpe:2.3:a:helm:helm:2.16.0
-
cpe:2.3:a:helm:helm:2.16.1
-
cpe:2.3:a:helm:helm:2.16.10
-
cpe:2.3:a:helm:helm:2.16.2
-
cpe:2.3:a:helm:helm:2.16.3
-
cpe:2.3:a:helm:helm:2.16.4
-
cpe:2.3:a:helm:helm:2.16.5
-
cpe:2.3:a:helm:helm:2.16.6
-
cpe:2.3:a:helm:helm:2.16.7
-
cpe:2.3:a:helm:helm:2.16.8
-
cpe:2.3:a:helm:helm:2.16.9
-
cpe:2.3:a:helm:helm:2.2.0
-
cpe:2.3:a:helm:helm:2.2.1
-
cpe:2.3:a:helm:helm:2.2.2
-
cpe:2.3:a:helm:helm:2.2.3
-
cpe:2.3:a:helm:helm:2.3.0
-
cpe:2.3:a:helm:helm:2.3.1
-
cpe:2.3:a:helm:helm:2.4.0
-
cpe:2.3:a:helm:helm:2.4.1
-
cpe:2.3:a:helm:helm:2.4.2
-
cpe:2.3:a:helm:helm:2.5.0
-
cpe:2.3:a:helm:helm:2.5.1
-
cpe:2.3:a:helm:helm:2.6.0
-
cpe:2.3:a:helm:helm:2.6.1
-
cpe:2.3:a:helm:helm:2.6.2
-
cpe:2.3:a:helm:helm:2.7.0
-
cpe:2.3:a:helm:helm:2.7.1
-
cpe:2.3:a:helm:helm:2.7.2
-
cpe:2.3:a:helm:helm:2.8.0
-
cpe:2.3:a:helm:helm:2.8.1
-
cpe:2.3:a:helm:helm:2.8.2
-
cpe:2.3:a:helm:helm:2.9.0
-
cpe:2.3:a:helm:helm:2.9.1
-
cpe:2.3:a:helm:helm:3.0.0
-
cpe:2.3:a:helm:helm:3.0.1
-
cpe:2.3:a:helm:helm:3.0.2
-
cpe:2.3:a:helm:helm:3.0.3
-
cpe:2.3:a:helm:helm:3.1.0
-
cpe:2.3:a:helm:helm:3.1.1
-
cpe:2.3:a:helm:helm:3.1.2
-
cpe:2.3:a:helm:helm:3.1.3
-
cpe:2.3:a:helm:helm:3.2.0
-
cpe:2.3:a:helm:helm:3.2.1
-
cpe:2.3:a:helm:helm:3.2.2
-
cpe:2.3:a:helm:helm:3.2.3
-
cpe:2.3:a:helm:helm:3.2.4
-
cpe:2.3:a:helm:helm:3.3.0
-
cpe:2.3:a:helm:helm:3.3.1