Impact
The vulnerability permits an attacker to write arbitrary files during the extraction of operator catalog images performed by oc‑mirror. By exploiting a path traversal flaw, the tool saves tar entries without ensuring that the resulting file paths stay within the intended destination directory. If an attacker can influence the input image or the extraction context, they could overwrite critical files on the host system, potentially leading to remote code execution or privilege escalation. The fault is a classic file‑system traversal weakness (CWE‑22) that can directly compromise confidentiality, integrity, and availability of the affected platform.
Affected Systems
Red Hat Assisted Installer for Red Hat OpenShift Container Platform 2 and Red Hat OpenShift Container Platform 4 are impacted when using oc‑mirror to mirror operator catalogs. Specific version information is not listed, so all supported releases that include the vulnerable oc‑mirror component are affected as long as they use the legacy v1 or OCI feature extraction paths.
Risk and Exploitability
The CVSS score of 7.3 indicates a moderately high severity. The EPSS score is not available, so the current exploitation likelihood is unknown, though the flaw is straightforward to leverage where oc‑mirror is run. The vulnerability is not listed in CISA’s KEV catalog, and there is no known public exploit at this time. The attack vector is inferred to be local or remote users who have the ability to run oc‑mirror with privileges sufficient to write to the host file system. An attacker who obtains such access could place malicious files or tamper with existing configurations during catalog extraction.
OpenCVE Enrichment