HIGH8.0
GHSA-84xv-jfrm-h4gm
registry-support: decompress can delete files outside scope via relative paths
Quick fix
GHSA-84xv-jfrm-h4gm — github.com/devfile/registry-support/registry-library: upgrade to the fixed version with the command below.
go get github.com/devfile/registry-support/registry-library@v0.0.0-20240206Details
A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the intended scope.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/devfile/registry-support/registry-library
Introduced in:
0Fixed in: 0.0.0-20240206Fix
go get github.com/devfile/registry-support/registry-library@v0.0.0-20240206References
- https://nvd.nist.gov/vuln/detail/CVE-2024-1485[ADVISORY]
- https://github.com/devfile/registry-support/pull/197[WEB]
- https://github.com/devfile/registry-support/commit/0e44b9ca6d03fac4fc3f77d37656d56dc5defe0d[WEB]
- https://access.redhat.com/security/cve/CVE-2024-1485[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2264106[WEB]
- https://github.com/advisories/GHSA-84xv-jfrm-h4gm[ADVISORY]
- https://github.com/devfile/registry-support[PACKAGE]