A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0570 | A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed. |
Github GHSA |
GHSA-84xv-jfrm-h4gm | registry-support: decompress can delete files outside scope via relative paths |
Fixes
Solution
No solution given by the vendor.
Workaround
Limit or block the parsing of devfiles from untrusted sources.
References
History
Wed, 25 Feb 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-73 |
Mon, 21 Oct 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devfile
Devfile registry-support Redhat openshift Developer Tools And Services |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:devfile:registry-support:*:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift:4.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_developer_tools_and_services:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Devfile
Devfile registry-support Redhat openshift Developer Tools And Services |
Fri, 27 Sep 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-02-25T19:30:57.278Z
Reserved: 2024-02-13T21:47:23.979Z
Link: CVE-2024-1485
Updated: 2024-08-01T18:40:21.236Z
Status : Modified
Published: 2024-02-14T00:15:46.783
Modified: 2026-02-25T20:17:19.877
Link: CVE-2024-1485
OpenCVE Enrichment
No data.
EUVD
Github GHSA