←back to thread

171 points irke882 | 1 comments | | HN request time: 0s | source
Show context
codebastard ◴[] No.44507439[source]
So the attack vector is:

- You have access to my file system

- You have access to the helm repository

You place malicious binaries outside the helm directory. Helm will now execute malicious code through the helm chart pointing outside the helm directory.

Don't I have already bigger problems if you have access to my file system to place there malicious code?

Is the danger here that one can get an execute permission? But if you can manipulate my helm chart why can you not also place the malicious code in the helm directory?

replies(4): >>44508017 #>>44508211 #>>44508268 #>>44512978 #
Joker_vD ◴[] No.44508211[source]
Yeah, there is a rather strong "downloading and executing arbitrary code from the Internet may lead to execution of arbitrary code" kind of vibe there.
replies(3): >>44508568 #>>44508594 #>>44508969 #
1. nijave ◴[] No.44508969[source]
Seems the normal mitigations apply i.e. validate with hash or save a local copy. Validate new versions before adopting