CVE-2024-1485
Published Feb 14, 2024
Last updated 25 days ago
Overview
- Description
- A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.3
- Impact score
- 5.8
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H
- Severity
- CRITICAL
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:devfile:registry-support:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8FDBF67C-FADA-4C25-9795-E099C8D0DB56", "versionEndExcluding": "0.0.0-20240206" }, { "criteria": "cpe:2.3:a:redhat:openshift:4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5F7E2F04-474D-4196-9CE8-242642990A16" }, { "criteria": "cpe:2.3:a:redhat:openshift_developer_tools_and_services:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "97321212-0E07-4CC2-A917-7B5F61AB9A5A" } ], "operator": "OR" } ] } ]