- Description
- A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.3
- Impact score
- 5.8
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H
- Severity
- CRITICAL
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:devfile:registry-support:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8FDBF67C-FADA-4C25-9795-E099C8D0DB56",
"versionEndExcluding": "0.0.0-20240206"
},
{
"criteria": "cpe:2.3:a:redhat:openshift:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F7E2F04-474D-4196-9CE8-242642990A16"
},
{
"criteria": "cpe:2.3:a:redhat:openshift_developer_tools_and_services:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "97321212-0E07-4CC2-A917-7B5F61AB9A5A"
}
],
"operator": "OR"
}
]
}
]