cbcvebase.
CVE-2024-0406
published 2024-04-06

CVE-2024-0406: A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

Affected

8 ranges
VendorProductVersion rangeFixed in
github.commholt_archiver0 – 3.5.1
github.commholt_archiver3.0.0 – 3.5.1
github.commholt_archiver_v30 – 3.5.1
github.commholt_archiver_v33.0.0 – 3.5.1
github.commholt_archiver_v3_github.com_mholt_archiver_v3v3.0.0 – v3.5.1
mholtarchiver>= 3.0.0 < 4.0.04.0.0
redhatadvanced_cluster_security
redhatopenshift_container_platform>= 4.18 < 4.18.44.18.4

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L
ghsa7.8HIGH
osv7.8HIGH