CVE-2024-1485P3MEDIUM≥ 0, < 0.0.0-202402062024-02-14
CVE-2024-1485 [MEDIUM] CWE-22 registry-support: decompress can delete files outside scope via relative paths
registry-support: decompress can delete files outside scope via relative paths
A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the in
ghsaosv