Publish Advisories

GHSA-7jr6-prv4-5wf5
GHSA-28r2-q6m8-9hpx
GHSA-cjr4-fv6c-f3mv
GHSA-p782-xgp4-8hr8
GHSA-qpgx-64h2-gc3c
GHSA-2m4x-4q9j-w97g
This commit is contained in:
advisory-database[bot]
2024-05-20 21:28:25 +00:00
parent c594cded35
commit 105e70fcc3
6 changed files with 10 additions and 9 deletions
@@ -1,13 +1,14 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7jr6-prv4-5wf5",
"modified": "2023-08-30T10:26:47Z",
"modified": "2024-05-20T21:26:28Z",
"published": "2021-06-23T18:14:31Z",
"withdrawn": "2024-05-20T21:26:28Z",
"aliases": [
"CVE-2021-32690"
],
"summary": "Helm passes repository credentials to alternate domain",
"details": "Helm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists where the username and password credentials associated with a Helm repository could be passed on to another domain referenced by that Helm repository. This issue has been resolved in 3.6.1. There is a workaround through which one may check for improperly passed credentials. One may use a username and password for a Helm repository and may audit the Helm repository in order to check for another domain being used that could have received the credentials. In the `index.yaml` file for that repository, one may look for another domain in the `urls` list for the chart versions. If there is another domain found and that chart version was pulled or installed, the credentials would be passed on.",
"summary": "Duplicate Advisory: Helm passes repository credentials to alternate domain",
"details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-56hp-xqp3-w2jf. This link is maintained to preserve external references.\n\n## Original Description\nHelm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists where the username and password credentials associated with a Helm repository could be passed on to another domain referenced by that Helm repository. This issue has been resolved in 3.6.1. There is a workaround through which one may check for improperly passed credentials. One may use a username and password for a Helm repository and may audit the Helm repository in order to check for another domain being used that could have received the credentials. In the `index.yaml` file for that repository, one may look for another domain in the `urls` list for the chart versions. If there is another domain found and that chart version was pulled or installed, the credentials would be passed on.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-28r2-q6m8-9hpx",
"modified": "2022-11-21T19:45:07Z",
"modified": "2024-05-20T21:27:04Z",
"published": "2022-05-26T00:01:27Z",
"aliases": [
"CVE-2022-30323"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cjr4-fv6c-f3mv",
"modified": "2022-11-21T19:45:28Z",
"modified": "2024-05-20T21:26:59Z",
"published": "2022-05-26T00:01:27Z",
"aliases": [
"CVE-2022-30322"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p782-xgp4-8hr8",
"modified": "2023-10-03T10:14:44Z",
"modified": "2024-05-20T21:27:32Z",
"published": "2022-06-24T00:00:30Z",
"aliases": [
"CVE-2022-29526"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qpgx-64h2-gc3c",
"modified": "2023-08-28T22:32:08Z",
"modified": "2024-05-20T21:27:26Z",
"published": "2022-06-17T01:03:47Z",
"aliases": [
"CVE-2022-25856"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2m4x-4q9j-w97g",
"modified": "2022-07-13T20:04:43Z",
"modified": "2024-05-20T21:27:56Z",
"published": "2022-07-01T00:01:03Z",
"aliases": [
"CVE-2022-33082"