Devfile Registry-support

CPE Details

Devfile Registry-support
-
2025-04-15
12h41 +00:00
2025-04-15
12h41 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:devfile:registry-support:-:*:*:*:*:*:*:*

Informations

Vendor

devfile

Product

registry-support

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-1485 2024-02-13 23h31 +00:00 A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.
9.3
Critical