HIGH 8.0 Go

registry-support: decompress can delete files outside scope via relative paths

GHSA-84xv-jfrm-h4gm · CVE-2024-1485 · GO-2024-2576

Published · Modified

Description

A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the intended scope.

Ready to move

Start Securing

Free, no credit card | First findings in minutes