CVE-2024-0406
Mholt/archiver: path traversal vulnerability
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.1EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
06 abr 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Productos afectados
archiverRed Hat · Red Hat Advanced Cluster Security 3Red Hat · Red Hat Advanced Cluster Security 4Red Hat · Red Hat OpenShift Container Platform 4.18¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →