An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.
History

Sun, 20 Apr 2025 16:00:00 +0000


Wed, 16 Apr 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat openshift Devspaces
CPEs cpe:/a:redhat:openshift_devspaces:3::el9
Vendors & Products Redhat
Redhat openshift Devspaces

Fri, 28 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Title tar-fs: link following and path traversal via maliciously crafted tar file
References
Metrics threat_severity

None

threat_severity

Important


Thu, 27 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
Description An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.
Weaknesses CWE-22
CWE-59
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: seal

Published: 2025-03-27T16:25:34.410Z

Updated: 2025-04-20T15:42:44.814Z

Reserved: 2024-12-23T13:53:01.494Z

Link: CVE-2024-12905

cve-icon Vulnrichment

Updated: 2025-03-27T18:24:06.268Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-27T17:15:53.250

Modified: 2025-04-20T16:15:13.913

Link: CVE-2024-12905

cve-icon Redhat

Severity : Important

Publid Date: 2025-03-27T16:25:34Z

Links: CVE-2024-12905 - Bugzilla