Database/Container, Kubernetes & orchestration
Helm: Malicious chart includes sensitive host content such as /etc/passwd, or triggers DoS, when loaded as a…
CVE-2019-18658Container, Kubernetes & orchestrationcurated
Impact
Malicious chart includes sensitive host content such as /etc/passwd, or triggers DoS, when loaded as a directory
Who can reach it
Malicious chart from a tenant or third-party repo
What to do
Upgrade Helm; never run helm package/helm lint on untrusted charts on a privileged host
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.