Skip to main content

Tiller Helm component is deployed

SeverityExploitabilityProvidersCategories
CRITICALMEDIUMKubernetesOTHER

Description

The Tiller Helm component served as a server component prior to Helm v3, enabling communication between the Helm client and the cluster.

However, Tiller Helm been deprecated since Helm v3 and should no longer be used.

Its removal has resulted in a simplified security model that directly integrates with Kubernetes' modern security, identity, and authorization mechanisms.

Impact

Potential data exposureVisible in logsUser interaction requiredPrivileges required
TrueFalseFalseFalse

Tiller Helm is no longer maintained and could introduce security vulnerabilities.

Remediation guidelines

Upgrade Helm to v3.

References

How can I help you ?