First published: Wed Mar 06 2024(Updated: )
An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor's position is that this behavior was introduced intentionally, and cannot be removed without breaking backwards compatibility (some users may be relying on these values). <a href="https://github.com/helm/helm/issues/7275">https://github.com/helm/helm/issues/7275</a> <a href="https://www.cncf.io/projects/helm/">https://www.cncf.io/projects/helm/</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Helm | <=3.13.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2268201 is high due to the exposure of sensitive data when using the --dry-run flag.
To mitigate REDHAT-BUG-2268201, avoid using the --dry-run flag in environments where secrets may be exposed.
CNCF Helm versions up to and including 3.13.3 are affected by REDHAT-BUG-2268201.
REDHAT-BUG-2268201 involves the display of secret values when the --dry-run flag is utilized.
As of now, there is no specific patch mentioned for REDHAT-BUG-2268201, but updating to later versions may resolve the issue.