Potential Vulnerability
What happened?
The CERT Coordination Center has a multi-vendor/developer case regarding a vulnerability which may affect this library. We request that a security representative respond to the [email protected] address and request an account be approved for anyone responsible for security or maintenance of the project.
Information for vendors can be found here: https://certcc.github.io/VINCE-docs/For-Vendors/
What did you expect to happen?
CERT Coordination Center asks that a representative join our vulnerability handling platform. Once on the platform, Helm/helm will be provided with a set of files specific to helm. As this is a public bug report, we will refrain from posting any files.
Best, CERT Coordination Center
How can we reproduce it (as minimally and precisely as possible)?
As this is a public bug report form, the CERT/CC will refrain from posting any files.
Helm version
helm ≤ v3.16.3
Kubernetes version
unknown
Source: helm/helm