An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS04NHh2LWpmcm0taDRnbc4AA5Rh

Moderate CVSS: 4.6 EPSS: 0.00807% (0.73124 Percentile) EPSS:

registry-support: decompress can delete files outside scope via relative paths

Affected Packages Affected Versions Fixed Versions
go:github.com/devfile/registry-support/registry-library
PURL: pkg:go/github.com%2Fdevfile%2Fregistry-support%2Fregistry-library
< 0.0.0-20240206 0.0.0-20240206
22 Dependent packages
65 Dependent repositories

Affected Version Ranges

All affected versions

All unaffected versions

A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the intended scope.

References: