Skip to content

CVE's in Helm 3.10.2 and 3.10.3 #11654

@SaradaSastri

Description

@SaradaSastri

Output of helm version: helm.sh/helm/v3 v3.10.2

Output of kubectl version: n/a

Cloud Provider/Platform (AKS, GKE, Minikube etc.): n/a

We are using the latest version of Helm 3.10.2 to find the below CVE's. Please fix them in your next release.

github.com/docker/docker - v20.10.17+incompatible

Fixed version - 20.10.18

CVE-2022-30630--high
CVE-2022-30631--high
CVE-2022-30632--high
CVE-2022-30633--high
CVE-2022-30635--high
CVE-2022-27664--high
CVE-2022-32189--high
CVE-2022-32190--high
CVE-2022-28131--high
CVE-2022-36109--medium
CVE-2022-1705--medium
CVE-2022-1962--medium
CVE-2022-32148--medium

github.com/containerd/containerd -v1.6.6

Fixed version
1.5.14, 1.6.7, 1.7.0b0
1.5.14, 1.6.9, 1.7.0b0
1.5.15, 1.6.10
1.5.16, 1.6.12

CVE's
CVE-2022-30631--high
CVE-2022-2879--high
CVE-2022-28131--high
CVE-2022-30630--high
CVE-2019-2054--high
CVE-2022-2880--high
CVE-2022-41716--high
CVE-2022-30633--high
CVE-2022-30632--high
CVE-2022-32189--high
CVE-2022-30635--high
CVE-2022-41720--high
CVE-2022-41715--high
CVE-2022-1705--medium
CVE-2022-1962--medium
CVE-2022-23471--medium
CVE-2022-32148--medium
CVE-2022-41717--medium

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions