In versions of helm prior to 3.6.1, a vulnerability exists where the
username and password credentials associated with a Helm repository
could be passed on to another domain referenced by that Helm
The index.yaml within a Helm chart repository contains a reference
where to get the chart archive for each version of a chart. The
reference can be relative to the index.yaml file or a URL to location.
The URL can point to any domain and this is a feature leveraged by Helm
users. For example, an index.yaml file can be hosted on GitHub pages
while the chart archives are hosted as GitHub releases. These are on
different domain names and the index.yaml file points to the other
When a username and password were associated with a Helm repository the
username and password were also passed on to other domains referenced
in the index.yaml file. This occurred when Helm went to retrieve a
specific chart archive on the other domain.