QID 997393
Date Published: 2024-02-22
QID 997393: GO (Go) Security Update for github.com/devfile/registry-support/registry-library (GHSA-84xv-jfrm-h4gm)
A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the intended scope.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-84xv-jfrm-h4gm for updates and patch information.
Vendor References
- GHSA-84xv-jfrm-h4gm -
github.com/advisories/GHSA-84xv-jfrm-h4gm
CVEs related to QID 997393
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-84xv-jfrm-h4gm | github.com/devfile/registry-support/registry-library |
|