cbcvebase.
CVE-2024-0406
published 2024-04-06

CVE-2024-0406: A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow…

PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.93%
56.5th percentile
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

Affected

8 ranges
VendorProductVersion rangeFixed in
github.commholt_archiver0 – 3.5.1
github.commholt_archiver3.0.0 – 3.5.1
github.commholt_archiver_v30 – 3.5.1
github.commholt_archiver_v33.0.0 – 3.5.1
github.commholt_archiver_v3_github.com_mholt_archiver_v3v3.0.0 – v3.5.1
mholtarchiver>= 3.0.0 < 4.0.04.0.0
redhatadvanced_cluster_security
redhatopenshift_container_platform>= 4.18 < 4.18.44.18.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa7.8HIGH
osv7.8HIGH
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.