VDB
CVE-2020-15186
CVE-2020-15186
PUBLISHED
In Helm before versions 2.16.11 and 3.3.2 plugin names are not sanitized properly. As a result, a malicious plugin author could use characters in a plugin name that would result in unexpected behavior, such as duplicating the name of another plugin or spoofing the output to `helm --help`. This issue has been patched in Helm 3.3.2. A possible workaround is to not install untrusted Helm plugins. Examine the `name` field in the `plugin.yaml` file for a plugin, looking for characters outside of the [a-zA-Z0-9._-] range.
EPSS 0.23% · 46.4th percentile
Risk Scores
EPSS Score
0.23%
46.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | helm | 2.0.0, 3.0.0 |
| Bitnami | helm | 2.0.0, 3.0.0 |
Exploit Intelligence
Timeline
- Sep 17, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score