A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the intended scope.
{
"cwe_ids": [
"CWE-22",
"CWE-23",
"CWE-73"
],
"github_reviewed": true,
"github_reviewed_at": "2024-02-21T23:18:42Z",
"nvd_published_at": "2024-02-14T00:15:46Z",
"severity": "MODERATE"
}