CVE-2024-1485
—CVSS 3.1
9.3 critical
EPSS
<1%p59
Published
()
Modified
Description
A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.
In the news0 stories
No ingested article mentions this CVE yet.