Onyxia-API Private Helm Repository Credentials Leak Vulnerability
Vulnerability
A vulnerability in Onyxia-API versions 4.6.0 prior to 4.9.0 allows the leakage of private helm repository credentials through the public, unauthenticated '/public/catalogs' endpoint. This issue affects only instances that have configured private helm repositories by setting a username and password in the catalogs configuration. The vulnerability was introduced in version 4.6.0 and has been fixed in version 4.9.0.
Impact
The vulnerability allows for unauthorized access to private helm repository credentials, which could be exploited to access or manipulate private helm charts or resources.
Remediation
Users can upgrade to Onyxia-API version 4.9.0 to address this vulnerability. For those unable to upgrade, removing private helm repositories from the catalogs configuration is recommended to prevent credential leakage.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
