chore(deps): update dependency renovate to v40 [security]#209
Open
renovate[bot] wants to merge 1 commit intomasterfrom
Open
chore(deps): update dependency renovate to v40 [security]#209renovate[bot] wants to merge 1 commit intomasterfrom
renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
454895c to
71d33bf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
32.17.1→40.33.0GitHub Vulnerability Alerts
GHSA-3f44-xw83-3pmg
Summary
The user-provided string
repositoryin thehelmv3manager is appended to thehelm registry logincommand without proper sanitization.Details
Adversaries can provide a maliciously crafted
Chart.yamlin conjunctions with a tweaked Renovate configuration file to trick Renovate to execute arbitrary code.The value for both uses of the
repositoryvariable in lib/modules/manager/helmv3/common.ts are not being escaped using thequotefunction from theshlexpackage.This lack of proper sanitization has been present in the product since version 31.51.0 (renovatebot/renovate@f372a68), released on January 24 of 2022.
PoC
renovate.json5:Chart.yaml:Chart.lock:kill 1, terminating the root process of the container.Note
This specific proof of concept was made a lot simpler with the introduction of the
overrideDatasourceconfiguration since version 38.120.0 (renovatebot/renovate@a70a6a3), released on October 12 of 2024, because it means that there is no more need for a proper response from an actual Helm registry on the malformed repository URL.Impact
This is a Arbitrary Command Injection vulnerability, allowing those with write access on repositories configured to be scanned by Renovate to cause the execution of commands of their choice on the machine that runs Renovate.
Severity
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HRelease Notes
renovatebot/renovate (renovate)
v40.33.0Compare Source
Features
react-springmonorepo (#36177) (cfa0990)Bug Fixes
Documentation
depNameandpackageName(#36063) (06d0e7c)Miscellaneous Chores
v40.32.7Compare Source
Bug Fixes
v40.32.6Compare Source
Build System
v40.32.5Compare Source
Build System
v40.32.4Compare Source
Build System
v40.32.3Compare Source
Miscellaneous Chores
Build System
v40.32.2Compare Source
Build System
v40.32.1Compare Source
Bug Fixes
Build System
v40.32.0Compare Source
Features
clusterctl(#36157) (035a561)Bug Fixes
v40.31.1Compare Source
Bug Fixes
CIenv to child processes (#36153) (49f1b00)Documentation
Miscellaneous Chores
Build System
v40.31.0Compare Source
Features
Miscellaneous Chores
v40.30.2Compare Source
Bug Fixes
v40.30.1Compare Source
Bug Fixes
Miscellaneous Chores
v40.30.0Compare Source
Features
Documentation
Miscellaneous Chores
v40.29.1Compare Source
Bug Fixes
v40.29.0Compare Source
Features
v40.28.0Compare Source
Features
v40.27.1Compare Source
Bug Fixes
v40.27.0Compare Source
Features
Documentation
v40.26.3Compare Source
Bug Fixes
v40.26.2Compare Source
Documentation
Miscellaneous Chores
Build System
v40.26.1Compare Source
Bug Fixes
v40.26.0Compare Source
Features
Miscellaneous Chores
a4b2b11(main) (#36101) (08b4ebd)v40.25.2Compare Source
Bug Fixes
v40.25.1Compare Source
Bug Fixes
Miscellaneous Chores
v40.25.0Compare Source
Features
docker_registry_imagedata source (#35537) (6ba08ec)Miscellaneous Chores
e3424ac(main) (#36095) (53cdf3f)v40.24.3Compare Source
Bug Fixes
v40.24.2Compare Source
Miscellaneous Chores
Build System
v40.24.1Compare Source
Build System
v40.24.0Compare Source
Features
Miscellaneous Chores
3592650(main) (#36088) (5560c3e)v40.23.2Compare Source
Bug Fixes
v40.23.1Compare Source
Miscellaneous Chores
Build System
v40.23.0Compare Source
Features
abandonmentThresholdand detectisAbandonedflag (#35866) (bc235fb)v40.22.1Compare Source
Bug Fixes
Miscellaneous Chores
v40.22.0Compare Source
Features
Miscellaneous Chores
721b561(main) (#36076) (7b7c690)v40.21.7Compare Source
Bug Fixes
v40.21.6Compare Source
Bug Fixes
v40.21.5Compare Source
Build System
v40.21.4Compare Source
Bug Fixes
Miscellaneous Chores
Build System
v40.21.3Compare Source
Bug Fixes
v40.21.2Compare Source
Bug Fixes
v40.21.1Compare Source
Bug Fixes
createdAtto mapped PR (#36058) (4341780)Miscellaneous Chores
v40.21.0Compare Source
Features
v40.20.0Compare Source
Features
Miscellaneous Chores
v40.19.2Compare Source
Bug Fixes
Miscellaneous Chores
v40.19.1Compare Source
Bug Fixes
v40.19.0Compare Source
Features
Bug Fixes
Miscellaneous Chores
v40.18.3Compare Source
Bug Fixes
v40.18.2Compare Source
Bug Fixes
v40.18.1Compare Source
Build System
v40.18.0Compare Source
Features
v40.17.1Compare Source
Build System
v40.17.0Compare Source
Features
v40.16.0Compare Source
Features
pnpcoremonorepo (#36020) (21ab01d)v40.15.0Compare Source
Features
Documentation
Miscellaneous Chores
v40.14.6Compare Source
Bug Fixes
ObsoleteCacheHitLogger(#36008) (78b0478)v40.14.5Compare Source
Build System
v40.14.4Compare Source
Bug Fixes
Documentation
Miscellaneous Chores
v40.14.3Compare Source
Bug Fixes
v40.14.2Compare Source
Bug Fixes
Code Refactoring
v40.14.1Compare Source
Bug Fixes
Miscellaneous Chores
v40.14.0Compare Source
Features
v40.13.1Compare Source
Bug Fixes
Miscellaneous Chores
v40.13.0Compare Source
Features
v40.12.4Compare Source
Bug Fixes
v40.12.3Compare Source
Miscellaneous Chores
Build System
v40.12.2Compare Source
Bug Fixes
Miscellaneous Chores
v40.12.1Compare Source
Build System
v40.12.0Compare Source
Features
Bug Fixes
Documentation
\n(#35959) (ed77dd5)Miscellaneous Chores
v40.11.19Compare Source
Bug Fixes
Miscellaneous Chores
Build System
v40.11.18Compare Source
Miscellaneous Chores
653b0cf(main) (#35940) (0b58ec4)Build System
v40.11.17Compare Source
Documentation
Build System
v40.11.16Compare Source
Miscellaneous Chores
Build System
v40.11.15Compare Source
Bug Fixes
Miscellaneous Chores
v40.11.14Compare Source
Bug Fixes
Miscellaneous Chores
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.