REDHAT-BUG-2268201: Medium severity helm vulnerability
An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor's position is that this behavior was introduced intentionally, and cannot be removed without breaking backwards compatibility (some users may be relying on these values).
https://github.com/helm/helm/issues/7275 https://www.cncf.io/projects/helm/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2268201?
The severity of REDHAT-BUG-2268201 is high due to the exposure of sensitive data when using the --dry-run flag.
How do I fix REDHAT-BUG-2268201?
To mitigate REDHAT-BUG-2268201, avoid using the --dry-run flag in environments where secrets may be exposed.
Which versions of CNCF Helm are affected by REDHAT-BUG-2268201?
CNCF Helm versions up to and including 3.13.3 are affected by REDHAT-BUG-2268201.
What is the nature of the issue in REDHAT-BUG-2268201?
REDHAT-BUG-2268201 involves the display of secret values when the --dry-run flag is utilized.
Is there a patch available for REDHAT-BUG-2268201?
As of now, there is no specific patch mentioned for REDHAT-BUG-2268201, but updating to later versions may resolve the issue.