Junglewise Threat Intelligence

CVE-2024-58376: Renovate arbitrary command injection via helmv3 registryAliases

CVE-2024-58376 · Severity: low · CVSS 3.1 · Published 2024-04-23

Technologies: Renovate. Vendors: npm.

Executive brief

Renovate is a popular automated dependency management tool used by development teams to keep project dependencies up to date. An attacker with commit access to a repository could inject malicious shell commands through Helm chart configuration, allowing them to execute arbitrary code in Renovate's execution environment (Docker containers, Kubernetes pods, or CI/CD pipelines). This could lead to exposure of credentials, secrets, and access to the underlying infrastructure.

Technical details

The vulnerability is a command injection flaw in the helmv3 manager's handling of registryAliases configuration. The vulnerable code constructs a `helm repo add` command without properly quoting the registry alias key, allowing attackers to inject shell metacharacters and arbitrary commands. The attack requires commit access to the default branch to modify renovate.json or helm chart files. An attacker can execute arbitrary shell commands in Renovate's execution environment by crafting a malicious registryAliases entry (e.g., `"foo/bar || sh -c 'ls /; exit 1'"`) that breaks out of the intended command structure. The vulnerability affects versions 37.158.0 through 37.199.0, with the fix applied in version 37.199.0 using proper shell escaping (shlex quoting).

Affected products

  • Renovate Renovate 37.158.0 to 37.199.0

Timeline

  • 2024-04-23: disclosed: GitHub Security Advisory published
  • 2024-04-23: patched: Fixed in version 37.199.0 with shlex quoting

References

Related threats