VDB
Sign up
MEDIUM6.5

GHSA-f9f8-9pmf-xv68

Helm May Panic Due To Incorrect YAML Content

Quick fix

GHSA-f9f8-9pmf-xv68 — helm.sh/helm/v3: upgrade to the fixed version with the command below.

go get helm.sh/helm/v3@v3.18.5

Details

A Helm contributor discovered an improper validation of type error when parsing Chart.yaml and index.yaml files that can lead to a panic.

### Impact

There are two areas of YAML validation that were impacted. First, when a `Chart.yaml` file had a `null` maintainer or the `child` or `parent` of a dependencies `import-values` could be parsed as something other than a string, `helm lint` would panic. Second, when an `index.yaml` had an empty entry in the list of chart versions Helm would panic on interactions with that repository.

### Patches

This issue has been resolved in Helm v3.18.5.

### Workarounds

Ensure YAML files are formatted as Helm expects prior to processing them with Helm.

### References

Helm's security policy is spelled out in detail in our [SECURITY](https://github.com/helm/community/blob/master/SECURITY.md) document.

### Credits

Disclosed by Jakub Ciolek at AlphaSense.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/helm.sh/helm/v3
Introduced in: 0Fixed in: 3.18.5
Fixgo get helm.sh/helm/v3@v3.18.5

References