The vendor explicitly identifies these products as affected by this CVE.
- multicluster-engine/assisted-service-9-rhel9 as a component of Multicluster Engine for Kubernetes
- rhacm2/multicluster-operators-subscription-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- Summary
- A flaw was found in go-billy, an interface filesystem abstraction for Go. Multiple path traversal vulnerabilities exist due to insufficient path sanitization and boundary enforcement. A remote attacker could exploit this by crafting malicious paths, allowing them to escape intended base directories. This could lead to unauthorized access to sensitive filesystem locations, potentially resulting in information disclosure or modification of files.
- Remediation
- Affected
