Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-0406

Опубликовано: 31 янв. 2024
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

Отчет

This is a path traversal vulnerability in v3 of mhol/archiver and has been marked as moderate for a variety of reasons. First and foremost the attacker in order to exploit this vulnerability would require local files system/code execution level access, this cannot be exploited on a network level, secondly, the successful exploitation of this vulnerability only result in overwriting of files, not denial of service due to resource exhaustion and no code execution, keeping all these things in mind redhat has assigned this as moderate impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Will not fix
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-roxctl-rhel8Will not fix
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-scanner-rhel8Will not fix
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-roxctl-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-rhel8Not affected
Red Hat OpenShift Container Platform 4.18openshift4/oc-mirror-plugin-rhel9FixedRHSA-2025:244911.03.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2257749mholt/archiver: path traversal vulnerability

EPSS

Процентиль: 58%
0.00928
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
больше 2 лет назад

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

CVSS3: 6.1
github
больше 2 лет назад

Archiver Path Traversal vulnerability

suse-cvrf
9 месяцев назад

Security update for hauler

EPSS

Процентиль: 58%
0.00928
Низкий

6.1 Medium

CVSS3