registry-support: decompress can delete files outside scope via relative paths
Moderate severity
GitHub Reviewed
Published
Feb 14, 2024
to the GitHub Advisory Database
•
Updated Nov 18, 2024
Package
Affected versions
< 0.0.0-20240206
Patched versions
0.0.0-20240206
Description
Published by the National Vulnerability Database
Feb 14, 2024
Published to the GitHub Advisory Database
Feb 14, 2024
Reviewed
Feb 21, 2024
Last updated
Nov 18, 2024
A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the intended scope.
References