First published: Wed Dec 14 2022(Updated: )
A flaw was found in Helm. Applications that use the _repo_ package in Helm SDK to parse an index file may suffer a denial of service when that input causes a panic that cannot be recovered from. The Helm Client will panic with an index file that causes a memory violation panic.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/helm.sh/helm/v3 | <3.10.3 | 3.10.3 |
Helm Helm | >=3.0.0<3.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23525 is a vulnerability in Helm that can cause a Denial of Service (DoS) attack.
CVE-2022-23525 affects applications that use the `_repo_` package in Helm SDK and can lead to a DoS attack.
CVE-2022-23525 has a severity rating of 7.5 (High).
The remedy for CVE-2022-23525 is to upgrade to Helm version 3.10.3.
More information about CVE-2022-23525 can be found at the following references: [CVE-2022-23525](https://www.cve.org/CVERecord?id=CVE-2022-23525), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-23525), [GitHub commit](https://github.com/helm/helm/commit/638ebffbc2e445156f3978f02fd83d9af1e56f5b), [GitHub security advisory](https://github.com/helm/helm/security/advisories/GHSA-53c4-hhmh-vw5q), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2154202), [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2023:1646).