Onyxia-API Private Helm Repository Credentials Leak Vulnerability

Vulnerability

A vulnerability in Onyxia-API versions 4.6.0 prior to 4.9.0 allows the leakage of private helm repository credentials through the public, unauthenticated '/public/catalogs' endpoint. This issue affects only instances that have configured private helm repositories by setting a username and password in the catalogs configuration. The vulnerability was introduced in version 4.6.0 and has been fixed in version 4.9.0.

Impact

The vulnerability allows for unauthorized access to private helm repository credentials, which could be exploited to access or manipulate private helm charts or resources.

Remediation

Users can upgrade to Onyxia-API version 4.9.0 to address this vulnerability. For those unable to upgrade, removing private helm repositories from the catalogs configuration is recommended to prevent credential leakage.

Added: Sep 5, 2025, 10:20 PM
Updated: Sep 5, 2025, 10:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.5
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.