QID 997393

Date Published: 2024-02-22

QID 997393: GO (Go) Security Update for github.com/devfile/registry-support/registry-library (GHSA-84xv-jfrm-h4gm)

A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the intended scope.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-84xv-jfrm-h4gm for updates and patch information.
    Vendor References

    CVEs related to QID 997393

    Software Advisories
    Advisory ID Software Component Link
    GHSA-84xv-jfrm-h4gm github.com/devfile/registry-support/registry-library URL Logo github.com/advisories/GHSA-84xv-jfrm-h4gm