The vendor explicitly identifies these products as affected by this CVE.
- openshift-update-service/openshift-update-service-rhel8 as a component of Red Hat OpenShift Update Service
- Summary
- A flaw was found in tar-rs. This vulnerability, a symlink escape, allows a local attacker to read sensitive files outside of the intended directory. By planting specially crafted symbolic links in an untrusted directory, an attacker can trick a privileged process, when archiving that directory, into including arbitrary files from the system. This leads to the disclosure of potentially confidential information to the attacker.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
