GHSA-hpxr-w9w7-g4gv
stereoscope vulnerable to tar path traversal when processing OCI tar archives
Quick fix
GHSA-hpxr-w9w7-g4gv — github.com/anchore/stereoscope: upgrade to the fixed version with the command below.
go get github.com/anchore/stereoscope@v0.0.1Details
### Impact It is possible to craft an OCI tar archive that, when stereoscope attempts to unarchive the contents, will result in writing to paths outside of the unarchive temporary directory. Specifically, use of `github.com/anchore/stereoscope/pkg/file.UntarToDirectory()` function, the `github.com/anchore/stereoscope/pkg/image/oci.TarballImageProvider` struct, or the higher level `github.com/anchore/stereoscope/pkg/image.Image.Read()` function express this vulnerability.
### Patches Patched in v0.0.1
### Workarounds If you are using the OCI archive as input into stereoscope then you can switch to using an [OCI layout](https://github.com/opencontainers/image-spec/blob/main/image-layout.md) by unarchiving the tar archive and provide the unarchived directory to stereoscope.
### References - Patch PR https://github.com/anchore/stereoscope/pull/214
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.0.1go get github.com/anchore/stereoscope@v0.0.1