← Back

CVE-2024-0406

nvd nist
Published: Apr 6, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

Affected (3)

1 product
Archiver
2 products
Advanced Cluster Security
Openshift Container Platform
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 3.0.0 to 4.0.0
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0
From 4.18 to 4.18.4

References (5)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.