Логотип exploitDog
bind:CVE-2024-24579
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-24579

Количество 2

Количество 2

nvd логотип

CVE-2024-24579

около 2 лет назад

stereoscope is a go library for processing container images and simulating a squash filesystem. Prior to version 0.0.1, it is possible to craft an OCI tar archive that, when stereoscope attempts to unarchive the contents, will result in writing to paths outside of the unarchive temporary directory. Specifically, use of `github.com/anchore/stereoscope/pkg/file.UntarToDirectory()` function, the `github.com/anchore/stereoscope/pkg/image/oci.TarballImageProvider` struct, or the higher level `github.com/anchore/stereoscope/pkg/image.Image.Read()` function express this vulnerability. As a workaround, if you are using the OCI archive as input into stereoscope then you can switch to using an OCI layout by unarchiving the tar archive and provide the unarchived directory to stereoscope.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-hpxr-w9w7-g4gv

около 2 лет назад

stereoscope vulnerable to tar path traversal when processing OCI tar archives

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-24579

stereoscope is a go library for processing container images and simulating a squash filesystem. Prior to version 0.0.1, it is possible to craft an OCI tar archive that, when stereoscope attempts to unarchive the contents, will result in writing to paths outside of the unarchive temporary directory. Specifically, use of `github.com/anchore/stereoscope/pkg/file.UntarToDirectory()` function, the `github.com/anchore/stereoscope/pkg/image/oci.TarballImageProvider` struct, or the higher level `github.com/anchore/stereoscope/pkg/image.Image.Read()` function express this vulnerability. As a workaround, if you are using the OCI archive as input into stereoscope then you can switch to using an OCI layout by unarchiving the tar archive and provide the unarchived directory to stereoscope.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-hpxr-w9w7-g4gv

stereoscope vulnerable to tar path traversal when processing OCI tar archives

CVSS3: 5.3
0%
Низкий
около 2 лет назад

Уязвимостей на страницу