CVE-2024-1485
published 2024-02-14CVE-2024-1485: A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into…
PriorityP350critical9.3CVSS 3.1
AVNACLPRNUIRSCCNIHAH
EPSS
0.94%
57.0th percentile
A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| devfile | registry-support | < 0.0.0-20240206 | 0.0.0-20240206 |
| github.com | devfile_registry-support_registry-library | >= 0 < 0.0.0-20240206 | 0.0.0-20240206 |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.19.3CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
registry-support: decompress can delete files outside scope via relative paths in github.com/devfile/registry-support/registry-library
osv·2024-06-05
CVE-2024-1485 registry-support: decompress can delete files outside scope via relative paths in github.com/devfile/registry-support/registry-library
registry-support: decompress can delete files outside scope via relative paths in github.com/devfile/registry-support/registry-library
registry-support: decompress can delete files outside scope via relative paths in github.com/devfile/registry-support/registry-library.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/devfile/registry-support/registry-library before v0.0.0-20240206.
GHSA
registry-support: decompress can delete files outside scope via relative paths
ghsa·2024-02-14
CVE-2024-1485 [MEDIUM] CWE-22 registry-support: decompress can delete files outside scope via relative paths
registry-support: decompress can delete files outside scope via relative paths
A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the intended scope.
OSV
registry-support: decompress can delete files outside scope via relative paths
osv·2024-02-14
CVE-2024-1485 [MEDIUM] registry-support: decompress can delete files outside scope via relative paths
registry-support: decompress can delete files outside scope via relative paths
A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the intended scope.
Red Hat
registry-support: decompress can delete files outside scope via relative paths
vendor_redhat·2024-02-05·CVSS 8.0
CVE-2024-1485 [HIGH] CWE-22 registry-support: decompress can delete files outside scope via relative paths
registry-support: decompress can delete files outside scope via relative paths
A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.
A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which shou
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2024-1485https://bugzilla.redhat.com/show_bug.cgi?id=2264106https://github.com/advisories/GHSA-84xv-jfrm-h4gmhttps://github.com/devfile/registry-support/commit/0e44b9ca6d03fac4fc3f77d37656d56dc5defe0dhttps://github.com/devfile/registry-support/pull/197https://access.redhat.com/security/cve/CVE-2024-1485https://bugzilla.redhat.com/show_bug.cgi?id=2264106https://github.com/advisories/GHSA-84xv-jfrm-h4gmhttps://github.com/devfile/registry-support/commit/0e44b9ca6d03fac4fc3f77d37656d56dc5defe0dhttps://github.com/devfile/registry-support/pull/197
2024-02-14
Published