7.8
CVE-2024-0406
- EPSS 13.5%
- Veröffentlicht 06.04.2024 17:15:07
- Zuletzt bearbeitet 25.04.2025 15:02:44
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Advanced Cluster Security Version3.0
Redhat ≫ Openshift Container Platform Version >= 4.18 < 4.18.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 13.5% | 0.939 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| secalert@redhat.com | 6.1 | 1.8 | 4.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.