CVE-2020-7919: High severity Golang Go vulnerability
Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.
Other sources
The Helm core maintainers have identified a high severity security vulnerability in Go's crypto package affecting all versions prior to Helm 2.16.8 and Helm 3.1.0.
Thanks to @ravin9249 for identifying the vulnerability.
Impact
Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients resulting in a panic via a malformed X.509 certificate. This may allow a remote attacker to cause a denial of service.
Patches
A patch to compile Helm against Go 1.14.4 has been provided for Helm 2 and is available in Helm 2.16.8. Helm 3.1.0 and newer are compiled against Go 1.13.7+.
Workarounds
No workaround is available. Users are urged to upgrade.
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-7919 - https://github.com/helm/helm/pull/8288
For more information
If you have any questions or comments about this advisory:
Open an issue in the Helm repository For security-specific issues, email us at <cncf-helm-security@lists.cncf.io>
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/golang-1.11to a version that resolves this vulnerability.Fixed in 1.11.6-1+deb10u4Fixed in 1.11.6-1+deb10u7 - Upgrade
Upgrade
go/helm.sh/helm/v3to a version that resolves this vulnerability.Fixed in 3.1.0 - Upgrade
Upgrade
go/golang.org/x/cryptoto a version that resolves this vulnerability.Fixed in 0.0.0-20200124225646-8b5121be2f68 - Upgrade
Upgrade
go/github.com/helm/helmto a version that resolves this vulnerability.Fixed in 2.16.8 - Upgrade
Upgrade
Helm 2to a version that resolves this vulnerability.Fixed in 2.16.8 - Upgrade
Upgrade
Helm 3to a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
What is the vulnerability ID for this security vulnerability?
The vulnerability ID for this security vulnerability is CVE-2020-7919.
What is the severity of CVE-2020-7919?
The severity of CVE-2020-7919 is high (7.5).
Which versions of Go's `crypto` package are affected by CVE-2020-7919?
Versions of Go's `crypto` package before 0.0.0-20200124225646-8b5121be2f68 are affected by CVE-2020-7919.
Which versions of Helm are affected by CVE-2020-7919?
Versions of Helm prior to 2.16.8 and 3.1.0 are affected by CVE-2020-7919.
How can I fix CVE-2020-7919?
To fix CVE-2020-7919, update your version of Go's `crypto` package to 0.0.0-20200124225646-8b5121be2f68, or update Helm to version 2.16.8 or 3.1.0.