CVE-2024-0406

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mholt:archiver:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:advanced_cluster_security:3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*

History

25 Apr 2025, 15:02

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:advanced_cluster_security:3.0:*:*:*:*:*:*:*
cpe:2.3:a:mholt:archiver:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*
First Time Redhat openshift Container Platform
Mholt
Redhat
Redhat advanced Cluster Security
Mholt archiver
References () https://access.redhat.com/errata/RHSA-2025:2449 - () https://access.redhat.com/errata/RHSA-2025:2449 - Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2024-0406 - () https://access.redhat.com/security/cve/CVE-2024-0406 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2257749 - () https://bugzilla.redhat.com/show_bug.cgi?id=2257749 - Third Party Advisory

11 Mar 2025, 04:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:2449 -

21 Nov 2024, 08:46

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2024-0406 - () https://access.redhat.com/security/cve/CVE-2024-0406 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2257749 - () https://bugzilla.redhat.com/show_bug.cgi?id=2257749 -

06 Apr 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-06 17:15

Updated : 2025-04-25 15:02


NVD link : CVE-2024-0406

Mitre link : CVE-2024-0406

CVE.ORG link : CVE-2024-0406


JSON object : View

Products Affected

mholt

  • archiver

redhat

  • advanced_cluster_security
  • openshift_container_platform
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')