CVE-2023-25165
Summary
| CVE | CVE-2023-25165 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-08 20:15:00 UTC |
| Updated | 2023-02-16 20:10:00 UTC |
| Description | Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with `helm install|upgrade|template` or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject `getHostByName` into a chart in order to disclose values to a malicious DNS server. The issue has been fixed in Helm 3.11.1. Prior to using a chart with Helm verify the `getHostByName` function is not being used in a template to disclose any information you do not want passed to DNS servers. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Merge pull request from GHSA-pwcw-6f5g-gxf8 · helm/helm@5abcf74 · GitHub | MISC | github.com | |
| getHostByName Function Information Disclosure · Advisory · helm/helm · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 905440 Common Base Linux Mariner (CBL-Mariner) Security Update for cert-manager (13300)
- 905547 Common Base Linux Mariner (CBL-Mariner) Security Update for helm (13557)
- 905548 Common Base Linux Mariner (CBL-Mariner) Security Update for helm (13558)
- 906527 Common Base Linux Mariner (CBL-Mariner) Security Update for helm (13558-1)
- 906537 Common Base Linux Mariner (CBL-Mariner) Security Update for helm (13557-1)
- 906569 Common Base Linux Mariner (CBL-Mariner) Security Update for helm (13557-3)
- 906682 Common Base Linux Mariner (CBL-Mariner) Security Update for helm (13558-3)
- 906790 Common Base Linux Mariner (CBL-Mariner) Security Update for helm (13557-5)
- 906940 Common Base Linux Mariner (CBL-Mariner) Security Update for cert-manager (13300-1)
- 906997 Common Base Linux Mariner (CBL-Mariner) Security Update for cert-manager (13300-2)