Vulnerability Report: GO-2021-0099
- CVE-2021-21272, GHSA-g5v4-5x39-vwhx
- Affects: github.com/deislabs/oras
- Published: Apr 14, 2021
- Modified: May 20, 2024
Due to improper path validation, using the github.com/deislabs/oras/pkg/content.FileStore content store may result in directory traversal during archive extraction, allowing a malicious archive to write paths to arbitrary paths that the process can write to.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.9.0
2 unexported affected symbols
- extractTarDirectory
- fileWriter.Commit
Aliases
References
- https://github.com/deislabs/oras/commit/96cd90423303f1bb42bd043cb4c36085e6e91e8e
- https://vuln.go.dev/ID/GO-2021-0099.json
Credits
- Chris Smowton
Feedback
See anything missing or incorrect?
Suggest an edit to this report.