CVE-2024-0406

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mholt:archiver:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:advanced_cluster_security:3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*

History

25 Apr 2025, 15:02

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:advanced_cluster_security:3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:mholt:archiver:*:*:*:*:*:*:*:*
First Time Redhat advanced Cluster Security
Redhat
Redhat openshift Container Platform
Mholt archiver
Mholt
References () https://access.redhat.com/errata/RHSA-2025:2449 - () https://access.redhat.com/errata/RHSA-2025:2449 - Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2024-0406 - () https://access.redhat.com/security/cve/CVE-2024-0406 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2257749 - () https://bugzilla.redhat.com/show_bug.cgi?id=2257749 - Third Party Advisory

11 Mar 2025, 04:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:2449 -

Information

Published : 2024-04-06 17:15

Updated : 2025-04-25 15:02


NVD link : CVE-2024-0406

Mitre link : CVE-2024-0406

CVE.ORG link : CVE-2024-0406


JSON object : View

Products Affected

mholt

  • archiver

redhat

  • openshift_container_platform
  • advanced_cluster_security
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')