The vendor explicitly identifies these products as affected by this CVE.
- endpoint-metrics-operator.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- multicloud-operators-subscription-release.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- multicloud-operators-subscription.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- multicluster-monitoring-operator.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- search-collector.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- rox.src as a component of Red Hat Advanced Cluster Security 3
- openshift4/cnf-tests-rhel8 as a component of Red Hat OpenShift Container Platform 4
- openshift4/compliance-rhel8-operator as a component of Red Hat OpenShift Container Platform 4
- openshift4/file-integrity-rhel8-operator as a component of Red Hat OpenShift Container Platform 4
- openshift4/ose-ansible-rhel9-operator as a component of Red Hat OpenShift Container Platform 4
- openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4
- openshift4/ose-helm-operator as a component of Red Hat OpenShift Container Platform 4
- Summary
- A flaw was found in oras. The directory support feature allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs `oras pull`.
- Remediation
- Fix deferred
