Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-12905

Опубликовано: 27 мар. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.

A flaw was found in the tar-fs package for Node.js. In affected versions, unauthorized file writes or overwrites outside the intended extraction directory can occur when extracting a maliciously crafted tar file. The issue is associated with index.js in the tar-fs package.

Отчет

This vulnerability is rated as an important severity because it allows attackers to extract a malicious tar file that can write or overwrite files outside the intended directory. This occurs due to improper handling of link resolution and pathname limitations. The risk is high for systems that automatically extract tar files, as it can lead to data corruption or unauthorized file modifications without user interaction.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 8cephAffected
Red Hat Ceph Storage 9cephAffected
Red Hat OpenShift Dev Spaces 3 Containersdevspaces/pluginregistry-rhel9FixedRHSA-2025:393216.04.2025
Red Hat OpenShift Dev Spaces 3 Containersdevspaces/code-rhel9FixedRHSA-2025:824428.05.2025
Red Hat OpenShift Dev Spaces 3 Containersdevspaces/configbump-rhel9FixedRHSA-2025:824428.05.2025
Red Hat OpenShift Dev Spaces 3 Containersdevspaces/dashboard-rhel9FixedRHSA-2025:824428.05.2025
Red Hat OpenShift Dev Spaces 3 Containersdevspaces/devspaces-operator-bundleFixedRHSA-2025:824428.05.2025
Red Hat OpenShift Dev Spaces 3 Containersdevspaces/devspaces-rhel9-operatorFixedRHSA-2025:824428.05.2025
Red Hat OpenShift Dev Spaces 3 Containersdevspaces/imagepuller-rhel9FixedRHSA-2025:824428.05.2025
Red Hat OpenShift Dev Spaces 3 Containersdevspaces/machineexec-rhel9FixedRHSA-2025:824428.05.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2355460tar-fs: link following and path traversal via maliciously crafted tar file

EPSS

Процентиль: 81%
0.02205
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.

CVSS3: 7.5
nvd
больше 1 года назад

An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.

CVSS3: 7.5
msrc
6 дней назад

An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.

CVSS3: 7.5
debian
больше 1 года назад

An Improper Link Resolution Before File Access ("Link Following") and ...

CVSS3: 7.5
github
больше 1 года назад

tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File

EPSS

Процентиль: 81%
0.02205
Низкий

7.5 High

CVSS3