The vendor explicitly identifies these products as affected by this CVE.
- compliance/openshift-compliance-content-rhel8 as a component of File Integrity Operator
- Summary
- A flaw was found in compliance-trestle. The library's profile import mechanism, which handles `trestle://` URIs and relative file paths, does not properly validate paths. This allows a remote attacker to craft a malicious OSCAL (Open Security Controls Assessment Language) profile YAML file containing path traversal sequences. Successful exploitation could enable the attacker to read arbitrary files from the server's filesystem, potentially leading to sensitive information disclosure.
- Remediation
- To mitigate this issue, ensure that only trusted OSCAL profile YAML files are imported and processed by systems utilizing `compliance-trestle`. Avoid importing or processing OSCAL profile YAML files from untrusted or unverified sources.
