Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39235
HistoryFeb 12, 2023 - 2:31 p.m.

Information Disclosure

2023-02-1214:31:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
github
helm
vulnerability
information disclosure
dns lookup
ip addresses
malicious dns server
gethostbyname
software

EPSS

0.001

Percentile

25.5%

github.com/helm/helm is vulnerable to Information Disclosure. The vulnerability is due to the DNS lookup chart that can disclose IP addresses to a malicious DNS server, which are used to lookup IP addresses when used with the helm install|upgrade|template command via the vulnerable getHostByName function.