helm是一款Kubernetes包管理器。 Helm 2.16.11 之前版本和3.3.2版本存在注入漏洞,该漏洞源于没有正确清理插件名,攻击者可利用该漏洞在插件名称中使用非法字符进行攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-15184 | 3.7 LOW | Aliases are never checked in Helm |
| CVE-2020-15187 | 3.0 LOW | Duplicate plugin entries in Helm |
| CVE-2020-15185 | 2.2 LOW | Duplicated chart entries in Helm |
No comments yet