Skip to content

Vulnerabilities with the k8sGPT v0.3.29

High
AlexsJones published GHSA-85rg-8m6h-825p Jun 13, 2024

Package

helm.sh/helm/v3

Affected versions

v3.13.3

Patched versions

None
helm.sh/helm/v3/pkg/chart
< 3.14.1
> 3.14.1
helm.sh/helm/v3/pkg/repo
< 3.14.2
> 3.14.2

Description

Summary

Found a bunch of vulnerabilities with the latest version of k8sGPT. Please can you help remediate these.

Details

Please refer to attached report.

Impact

Please refer to attachment.

Fixed in release https://github.com/k8sgpt-ai/k8sgpt/releases/tag/v0.3.33

Severity

High

CVE ID

No known CVE

Weaknesses

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Learn more on MITRE.

Use of Uninitialized Variable

The code uses a variable that has not been initialized, leading to unpredictable or unintended results. Learn more on MITRE.

Credits