CVE-2020-7919
ADVISORY - githubSummary
The Helm core maintainers have identified a high severity security vulnerability in Go's crypto
package affecting all versions prior to Helm 2.16.8 and Helm 3.1.0.
Thanks to @ravin9249 for identifying the vulnerability.
Impact
Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte
package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients resulting in a panic via a malformed X.509 certificate. This may allow a remote attacker to cause a denial of service.
Patches
A patch to compile Helm against Go 1.14.4 has been provided for Helm 2 and is available in Helm 2.16.8. Helm 3.1.0 and newer are compiled against Go 1.13.7+.
Workarounds
No workaround is available. Users are urged to upgrade.
References
For more information
If you have any questions or comments about this advisory:
- Open an issue in the Helm repository
- For security-specific issues, email us at cncf-helm-security@lists.cncf.io
Common Weakness Enumeration (CWE)
Improper Certificate Validation
Improper Certificate Validation
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in