What is CVE-2024-58376?
This is a command injection vulnerability in the helmv3 manager within Renovate versions 37.158.0 up to 37.199.0. Attackers with commit access can exploit unescaped shell metacharacters in registryAliases keys to execute arbitrary commands on the host. Upgrading to the latest version is strongly recommended.
Azərbaycanca: Bu boşluq Renovate alətinin 37.158.0 ilə 37.199.0 versiyalarında helmv3 menecerində command injection zəifliyidir. İcazəsiz şəxslər commit girişi əldə edərək registryAliases parametrləri vasitəsilə serverdə ixtiyari əmrlər icra edə bilər. Təcili olaraq ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which Renovate versions are affected by CVE-2024-58376?
This command injection vulnerability exists in the helmv3 manager in Renovate versions 37.158.0 up to 37.199.0.
How to protect against CVE-2024-58376?
It is strongly recommended to immediately upgrade Renovate to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.