Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2022-36049

7.7 · HIGH
Published Sep 7, 2022 helm CWE-400 EPSS 1.09% (63th pctl)

Overview

CVE-2022-36049 is a high-severity vulnerability affecting helm helm. It was published on September 7, 2022 and has a CVSS 3.1 base score of 7.7 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.7, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

Technical Description

Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allows one to declaratively manage Helm chart releases. Helm controller is tightly integrated with the Helm SDK. A vulnerability found in the Helm SDK that affects flux2 v0.0.17 until v0.32.0 and helm-controller v0.0.4 until v0.23.0 allows for specific data inputs to cause high memory consumption. In some platforms, this could cause the controller to panic and stop processing reconciliations. In a shared cluster multi-tenancy environment, a tenant could create a HelmRelease that makes the controller panic, denying all other tenants from their Helm releases being reconciled. Patches are available in flux2 v0.32.0 and helm-controller v0.23.0.

Remediation

Check the references section for vendor advisories and patches from helm. Update helm to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
helm helm >= 3.0.0, < 3.9.4 Affected
fluxcd flux2 >= 0.0.17, < 0.32.0 Affected
fluxcd helm-controller >= 0.0.4, < 0.23.0 Affected

Frequently Asked Questions

What is CVE-2022-36049?

CVE-2022-36049 is a high-severity vulnerability affecting helm helm. It was published on September 7, 2022 and has a CVSS 3.1 base score of 7.7 (HIGH).

How severe is CVE-2022-36049?

This vulnerability has a CVSS 3.1 base score of 7.7, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2022-36049?

Check the references section for vendor advisories and patches from helm. Update helm to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2022-36049?

CyberStrike's AI-powered security agents can automatically detect CVE-2022-36049 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.