One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 2200501
Date de publication 2021-01-15 21:15:13 (vue: 2021-01-16 00:05:14)
Titre CVE-2021-21251
Texte OneDev is an all-in-one devops platform. In OneDev before version 4.0.3 there is a critical "zip slip" vulnerability. This issue may lead to arbitrary file write. The KubernetesResource REST endpoint untars user controlled data from the request body using TarUtils. TarUtils is a custom library method leveraging Apache Commons Compress. During the untar process, there are no checks in place to prevent an untarred file from traversing the file system and overriding an existing file. For a successful exploitation, the attacker requires a valid __JobToken__ which may not be possible to get without using any of the other reported vulnerabilities. But this should be considered a vulnerability in `io.onedev.commons.utils.TarUtils` since it lives in a different artifact and can affect other projects using it. This issue was addressed in 4.0.3 by validating paths in tar archive to only allow them to be in specified folder when extracted.
Envoyé Oui
Condensat 2021 21251 `io addressed affect all allow any apache arbitrary archive are artifact attacker before body but can checks commons compress considered controlled critical custom cve data devops different during endpoint existing exploitation extracted file folder from get issue jobtoken kubernetesresource lead leveraging library lives may method not one onedev only other overriding paths place platform possible prevent process projects reported request requires rest should since slip specified successful system tar tarutils tarutils` them traversing untar untarred untars user using utils valid validating version vulnerabilities vulnerability when which without write zip
Tags Vulnerability Guideline
Stories Uber
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: