Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-1485

Опубликовано: 05 фев. 2024
Источник: redhat
CVSS3: 8

Описание

A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the parent or plugin keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.

Отчет

Red Hat Openshift has a "Low" rated impact due to the affected code being shipped, but unused.

Меры по смягчению последствий

Limit or block the parsing of devfiles from untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesodoWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-consoleFix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-349->CWE-23
https://bugzilla.redhat.com/show_bug.cgi?id=2264106registry-support: decompress can delete files outside scope via relative paths

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
почти 2 года назад

A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.

CVSS3: 8
github
почти 2 года назад

registry-support: decompress can delete files outside scope via relative paths

8 High

CVSS3