Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7j4w-x8x8-5mvg

Опубликовано: 10 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 9.6

Описание

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.

Пакеты

Наименование

github.com/kubev2v/assisted-migration-agent

go
Затронутые версииВерсия исправления

< 0.16.0

0.16.0

EPSS

Процентиль: 22%
0.00291
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-22
CWE-59

Связанные уязвимости

CVSS3: 9.6
redhat
2 месяца назад

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.

CVSS3: 9.6
nvd
2 месяца назад

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.

EPSS

Процентиль: 22%
0.00291
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-22
CWE-59