MEDIUM
source-to-image: Unsanitized paths in tar.go:ExtractTarStreamFromTarReader() allow malicious containers to overwrite files on the client machine
Published Jun 12, 2018
6.5
MEDIUMCVSS 3.1
EPSS 1.34%
Description
Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An attacker who could trick a user into using the command to copy files locally, from a pod, could override files outside of the target directory of the command.
Affected products
-
- Version source-to-image 1.1.10StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Openshift Enterprise | Unsanitized Paths in Tar.go | n/a |
|
- < 1.1.10
No data.
Red Hat OpenShift Enterprise 3
source-to-image
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Enterprise 3 | source-to-image | Affected | n/a |
github.com/openshift/source-to-image
Go
Introduced 0 Fixed 1.1.10-0.20180427153919-f5cbcbc5cc6f
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/openshift/source-to-image | 0 | 1.1.10-0.20180427153919-f5cbcbc5cc6f |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (12)
- https://access.redhat.com/security/cve/CVE-2018-1103 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1563993 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1103 x_refsource_CONFIRMIssue Tracking
- https://github.com/advisories/GHSA-w55j-f7vx-6q37 Advisory
- https://github.com/openshift/source-to-image/commit/f5cbcbc5cc6f8cc2f479a7302443bea407a700cb
- https://github.com/openshift/source-to-image/pull/870
- https://github.com/snyk/zip-slip-vulnerability
- https://hansmi.ch/articles/2018-04-openshift-s2i-security
- https://nvd.nist.gov/vuln/detail/CVE-2018-1103
- https://pkg.go.dev/vuln/GO-2020-0026
- https://snyk.io/research/zip-slip-vulnerability
- https://www.cve.org/CVERecord?id=CVE-2018-1103
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 12, 2018
Updated Aug 5, 2024
Reserved Dec 4, 2017
Link CVE-2018-1103
CISA Vulnrichment
GHSA-W55J-F7VX-6Q37 Updated n/a