(no title)
mfer | 7 months ago
This doesn't affect things like installing or upgrading a chart. Dependencies aren't updated at that time.
mfer | 7 months ago
This doesn't affect things like installing or upgrading a chart. Dependencies aren't updated at that time.
ajross|7 months ago
True enough, but if you have a victim unpacking and building untrusted tarballs there's no security boundary being crossed, is there? You don't have to bother with this symlink nonsense, just update the install script to include your payload directly.
Honestly this vulnerability is dumb. I don't see any realistic scenario where it can be exploited by an unprivileged attacker.
url00|7 months ago