CVE-2024-0406

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mholt:archiver:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:advanced_cluster_security:3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*

History

25 Apr 2025, 15:02

Type Values Removed Values Added
First Time Redhat openshift Container Platform
Mholt
Redhat
Redhat advanced Cluster Security
Mholt archiver
CPE cpe:2.3:a:redhat:advanced_cluster_security:3.0:*:*:*:*:*:*:*
cpe:2.3:a:mholt:archiver:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*
References () https://access.redhat.com/errata/RHSA-2025:2449 - () https://access.redhat.com/errata/RHSA-2025:2449 - Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2024-0406 - () https://access.redhat.com/security/cve/CVE-2024-0406 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2257749 - () https://bugzilla.redhat.com/show_bug.cgi?id=2257749 - Third Party Advisory

11 Mar 2025, 04:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:2449 -

21 Nov 2024, 08:46

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2024-0406 - () https://access.redhat.com/security/cve/CVE-2024-0406 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2257749 - () https://bugzilla.redhat.com/show_bug.cgi?id=2257749 -

06 Apr 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-06 17:15

Updated : 2025-04-25 15:02


NVD link : CVE-2024-0406

Mitre link : CVE-2024-0406

CVE.ORG link : CVE-2024-0406


JSON object : View

Products Affected

redhat

  • openshift_container_platform
  • advanced_cluster_security

mholt

  • archiver
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')