Description
In Helm greater than or equal to 3.0.0 and less than 3.2.4, a path traversal attack is possible when installing Helm plugins from a tar archive over HTTP. It is possible for a malicious plugin author to inject a relative path into a plugin archive, and copy a file outside of the intended directory. This has been fixed in 3.2.4.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/helm/helm/security/advisories/GHSA-qq3j-xp49-j73f
Patch x_refsource_misc
https://github.com/helm/helm/commit/0ad800ef43d3b826f31a5ad8dfbb4fe05d143688
Release Notes x_refsource_misc
https://github.com/helm/helm/releases/tag/v3.2.4
Scores
CVSS v3
3.7
EPSS
0.0041
EPSS Percentile
61.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Details
CWE
CWE-22
Status
published
Products (2)
helm/helm
3.0.0 - 3.2.4
helm/v3
3.0.0 - 3.2.4Go
Published
Jun 16, 2020
Tracked Since
Feb 18, 2026