CVE-2024-1485

CVSS V2 None CVSS V3 None
Description
A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.
Overview
  • CVE ID
  • CVE-2024-1485
  • Assigner
  • redhat
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-13T23:31:14.427Z
  • Last Modified Date
  • 2024-04-25T16:27:09.123Z
History
Created Old Value New Value Data Type Notes
2024-06-26 06:06:50 Added to TrackCVE