VDB
Sign up
HIGH8.0

GHSA-84xv-jfrm-h4gm

registry-support: decompress can delete files outside scope via relative paths

Quick fix

GHSA-84xv-jfrm-h4gm — github.com/devfile/registry-support/registry-library: upgrade to the fixed version with the command below.

go get github.com/devfile/registry-support/registry-library@v0.0.0-20240206

Details

A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the intended scope.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/devfile/registry-support/registry-library
Introduced in: 0Fixed in: 0.0.0-20240206
Fixgo get github.com/devfile/registry-support/registry-library@v0.0.0-20240206

References