Bug 1156646 - (CVE-2019-18658) VUL-0: CVE-2019-18658: helm: commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd
(CVE-2019-18658)
VUL-0: CVE-2019-18658: helm: commands that deal with loading a chart as a dir...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/246893/
CVSSv3.1:SUSE:CVE-2019-18658:6.1:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-11-13 14:04 UTC by Wolfgang Frisch
Modified: 2022-05-31 13:17 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Frisch 2019-11-13 14:04:46 UTC
CVE-2019-18658

In Helm 2.x before 2.15.2, commands that deal with loading a chart as a
directory or packaging a chart provide an opportunity for a maliciously designed
chart to include sensitive content such as /etc/passwd, or to execute a denial
of service (DoS) via a special file such as /dev/urandom, via symlinks. No
version of Tiller is known to be impacted. This is a client-only issue.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-18658
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18658
https://helm.sh/blog/2019-10-30-helm-symlink-security-notice/
Comment 3 Jordi Massaguer 2019-12-10 15:50:15 UTC
For CaaSPv4 this will be released in 4.1.0. Fix is in. Leaving it open for CaaSPv3
Comment 8 Swamp Workflow Management 2020-01-13 23:17:08 UTC
SUSE-FU-2020:0089-1: An update that has 11 feature fixes can now be installed.

Category: feature (moderate)
Bug References: 1100838,1118897,1118898,1118899,1143813,1144065,1146991,1147142,1152861,1155810,1156646
CVE References: 
Sources used:
SUSE CaaS Platform 4.0 (src):    caasp-release-4.1.0-24.9.1, conmon-2.0.0-1.7.1, cri-o-1.16.0-3.22.2, cri-tools-1.16.1-3.7.1, helm-2.16.1-3.7.1, kubernetes-1.16.2-4.7.1, patterns-caasp-Node-1.15-1.16-1.2-3.11.1, patterns-caasp-Node-1.16-1.2-3.11.2, release-notes-caasp-4.1.20191218-4.16.2, skuba-1.2.1-3.21.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Gabriele Sonnu 2022-04-27 14:13:07 UTC
Done.
Comment 12 Swamp Workflow Management 2022-05-31 13:17:36 UTC
SUSE-SU-2022:1888-1: An update that solves one vulnerability and has one errata is now available.

Category: security (moderate)
Bug References: 1156646,1197728
CVE References: CVE-2019-18658
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    helm-mirror-0.3.1-150000.1.13.1
openSUSE Leap 15.3 (src):    helm-mirror-0.3.1-150000.1.13.1
SUSE Linux Enterprise Module for Containers 15-SP4 (src):    helm-mirror-0.3.1-150000.1.13.1
SUSE Linux Enterprise Module for Containers 15-SP3 (src):    helm-mirror-0.3.1-150000.1.13.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.