SCA: security update for helm.sh/helm/v3 (GHSA-q8q8-93cv-v6h8)

medium Tenable Self-Hosted Container Security Plugin ID 431960

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Their is an information disclosure vulnerability in Helm from version 3.1.0 and before version 3.2.0.
`lookup` is a Helm template function introduced in Helm v3. It is able to lookup resources in the cluster
to check for the existence of specific resources and get details about them. This can be used as part of
the process to render templates. The documented behavior of `helm template` states that it does not attach
to a remote cluster. However, a the recently added `lookup` template function circumvents this restriction
and connects to the cluster even during `helm template` and `helm install|update|delete|rollback --dry-
run`. The user is not notified of this behavior. Running `helm template` should not make calls to a
cluster. This is different from `install`, which is presumed to have access to a cluster in order to load
resources into Kubernetes. Helm 2 is unaffected by this vulnerability. A malicious chart author could
inject a `lookup` into a chart that, when rendered through `helm template`, performs unannounced lookups
against the cluster a user's `KUBECONFIG` file points to. This information can then be disclosed via
the output of `helm template`. This issue has been fixed in Helm 3.2.0 (CVE-2020-11013)

See Also

https://github.com/advisories/GHSA-q8q8-93cv-v6h8

Plugin Details

Severity: Medium

ID: 431960

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 8/7/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2020-11013

CVSS v3

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/27/2021

Vulnerability Publication Date: 4/24/2020

Reference Information

CVE: CVE-2020-11013

cwe: CWE-200