cvedb.io
CVE-2022-23525
MEDIUM · CVSS 5.3
EPSS exploitation probability: 0%
Published 2022-12-15T19:15:17.027 · Last modified 2026-06-17T04:30:17.910

Summary

Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the _repo_package. The _repo_ package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where charts are managed. The _repo_ package parses the index file of the repository and loads it into structures Go can work with. Some index files can cause array data structures to be created causing a memory violation. Applications that use the _repo_ package in the Helm SDK to parse an index file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The Helm Client will panic with an index file that causes a memory violation panic. Helm is

Affected products

helm — helm

Does this affect you?

Add your gear to cvedb and we'll alert you only when helm ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.