CVE-2019-1010275 describes a critical improper certificate validation vulnerability (CWE-295) affecting Helm versions prior to 2.7.2. This flaw allowed unauthorized clients to connect to the Helm server by accepting self-signed client certificates. With a CVSS score of 9.8 (CRITICAL), the vulnerability presents a severe risk, as an unauthenticated attacker could exploit it over the network with low complexity, leading to complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.7.2CPE matchmatch criteria | cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.