CVE-2024-25620
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-25620 affects Helm, a popular tool for managing Kubernetes Charts. This vulnerability occurs when the Helm client or SDK saves a chart with a `Chart.yaml` file containing a relative path change in its name. As a result, the chart is saved outside its expected directory, bypassing validation and linting checks. This issue could potentially lead to misconfiguration and security vulnerabilities. Helm users unable to upgrade immediately are advised to manually check all used charts for such path changes in their `Chart.yaml` files, including dependencies. The vulnerability has been addressed in Helm v3.14.1.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.