REDHAT-BUG-2456927: High severity Helm vulnerability
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Helmto a version that resolves this vulnerability.Fixed in 4.1.4
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2456927?
The severity of REDHAT-BUG-2456927 is categorized as high with a score of 7.
How do I fix REDHAT-BUG-2456927?
To fix REDHAT-BUG-2456927, upgrade Helm to version 4.1.4 or later.
What is the impact of REDHAT-BUG-2456927?
The impact of REDHAT-BUG-2456927 is that Helm can install plugins without proper signature verification, leading to potential security risks.
Which versions of Helm are affected by REDHAT-BUG-2456927?
Helm versions from 4.0.0 to 4.1.3 are affected by REDHAT-BUG-2456927.
What functionality in Helm is compromised by REDHAT-BUG-2456927?
The functionality compromised by REDHAT-BUG-2456927 is the ability to install plugins while enforcing signature verification.