CVE-2024-1485

HIGH

Devfile Registry-support < 0.0.0-20240206 - Path Traversal

Title source: rule

Description

A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.

Exploits (1)

Scores

CVSS v3 8.0
EPSS 0.0211
EPSS Percentile 84.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:H

Details

CWE
CWE-22
Status published
Products (6)
devfile/registry-support < 0.0.0-20240206
devfile/registry-support 0 - 0.0.0-20240206Go
Red Hat/OpenShift Developer Tools and Services
Red Hat/Red Hat OpenShift Container Platform 4
redhat/openshift 4.0
redhat/openshift_developer_tools_and_services
Published Feb 14, 2024
Tracked Since Feb 18, 2026