turkdevops / gitea

Git with a cup of tea, painless self-hosted git service
https://gitea.io
MIT License
0 stars 0 forks source link

CVE-2024-0406 (Medium) detected in github.com/mholt/archiver-v3.5.0 #144

Open mend-bolt-for-github[bot] opened 4 months ago

mend-bolt-for-github[bot] commented 4 months ago

CVE-2024-0406 - Medium Severity Vulnerability

Vulnerable Library - github.com/mholt/archiver-v3.5.0

Easily create & extract archives, and compress & decompress files of various formats

Path to dependency file: /go.mod

Path to vulnerable library: /go.mod

Dependency Hierarchy: - :x: **github.com/mholt/archiver-v3.5.0** (Vulnerable Library)

Found in base branch: main

Vulnerability Details

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

Publish Date: 2024-04-06

URL: CVE-2024-0406

CVSS 3 Score Details (6.1)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Local - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: High - Availability Impact: None

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with Mend here