Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-0406

Опубликовано: 31 янв. 2024
Источник: redhat
CVSS3: 6.1
EPSS Средний

Описание

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Will not fix
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-roxctl-rhel8Will not fix
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-scanner-rhel8Will not fix
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-roxctl-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-rhel8Not affected
Red Hat OpenShift Container Platform 4.18openshift4/oc-mirror-plugin-rhel9FixedRHSA-2025:244911.03.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2257749mholt/archiver: path traversal vulnerability

EPSS

Процентиль: 95%
0.17294
Средний

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
почти 2 года назад

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

CVSS3: 6.1
github
почти 2 года назад

Archiver Path Traversal vulnerability

suse-cvrf
около 2 месяцев назад

Security update for hauler

EPSS

Процентиль: 95%
0.17294
Средний

6.1 Medium

CVSS3