CVE-2024-28863

Aliases:GHSA-f5x3-32g6-xq36DEBIAN-CVE-2024-28863CGA-37w6-894f-r4f6CGA-5h69-3fj7-5qq2CGA-5hj7-wf3p-4vr6CGA-6rxq-vfpx-2w67CGA-6wj9-f28h-cv5gCGA-cfxh-p99r-2hrpCGA-fm2v-m95v-7pqmCGA-fw32-pf5m-hrvjCGA-hmw5-q7g4-9jwrCGA-hwhg-9xgx-pp4hCGA-m8v2-jx8p-fr9gCGA-mx83-qv5g-c4pgCGA-pj99-pq68-rx33CGA-2f74-72pm-vghxCGA-2fqj-f879-mq37CGA-2gr7-57v2-3gwpCGA-2x45-23v5-8678CGA-35c4-jpf4-gwgrCGA-3cg7-33hf-7rg6CGA-3r52-73mg-phrrCGA-4594-7j3g-4wjqCGA-4wc9-h376-c3pxCGA-52cj-rxx7-8634CGA-5g69-7vrw-vr24CGA-5j4m-59rr-5v3cCGA-5m3w-33cv-m8jhCGA-5pw6-vr4c-mhjvCGA-63jp-qc9p-c994CGA-64pf-737v-6mvxCGA-6j85-5f3f-r28wCGA-74wc-22f3-xvr5CGA-7gvf-x86p-jmw7CGA-7h4p-f4fv-6p48CGA-82p6-c5x5-hqwvCGA-88hc-fv2f-xfcxCGA-c2f6-8675-c8vxCGA-cjrr-hpf6-fx65CGA-gcjh-x73r-vqjgCGA-gfm6-cc2g-5c58CGA-gp5w-826p-hrchCGA-gpfv-q22w-82h2CGA-h57q-38v5-mprvCGA-h8gp-jwqh-c79jCGA-hg8w-5q9c-6f98CGA-hv3f-gpf7-qp99CGA-hv4f-g62h-7fg4CGA-mmxw-ph3p-r2pvCGA-mv57-x655-5w3wCGA-p7mp-8cf8-635vCGA-pc54-8497-rx8qCGA-pq2x-vmf8-4j8cCGA-prfq-cjjw-j5crCGA-q5m6-r96j-2qcxCGA-q8vg-8r57-hmxcCGA-qfpx-78q8-7vcvCGA-qmm4-hc78-4p9fCGA-qp78-6f6f-jxr4CGA-qq4q-p5wx-56wfCGA-qxm7-rg59-5qvmCGA-r3ww-f5j7-h8qcCGA-r42f-r7qf-573pCGA-r4hp-wrqq-x48gCGA-r63j-wh7p-p2p8CGA-r8qf-r5x9-cqcqCGA-rfpj-954g-mm76CGA-rv3r-v4c4-r9hjCGA-vq3h-jr3r-8c6vCGA-vqxv-fchc-2hjmCGA-w58c-2v6j-fwxwCGA-w72r-f2mj-r3vcCGA-w7gw-hf32-c22jCGA-wrx2-28g4-qxpjCGA-wxmp-4829-23pjCGA-x2qw-gjjf-ch7pCGA-x3mv-vw2c-3jcrCGA-x474-5wr3-gq72CGA-x48r-mv22-xmq2CGA-xcm4-wfjw-8rfcCGA-xm7w-jq2j-8h2xCGA-xvcg-gwrr-v9qp
Analyzed
Published: 21 Mar 2024, 22:10
Last modified:13 Feb 2025, 17:47

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.93% LOW
1% probability +0.48%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

21 Mar 2024, 22:10
Published
Vulnerability first disclosed
13 Feb 2025, 17:47
Last Modified
Vulnerability information updated

Description

node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.93% Percentile: 59%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguardjupyter-base-notebook

    all

  • chainguardlerna

    < 8.1.3-r0

  • chainguardnpm

    < 10.5.1-r0

  • chainguardopensearch-dashboards-2

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-alerting-dashboards-plugin

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-anomaly-detection-dashboards-plugin

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-config

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-dashboards-maps

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-dashboards-notifications

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-dashboards-observability

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-dashboards-query-workbench

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-dashboards-reporting

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-dashboards-search-relevance

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-dashboards-visualizations

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-alerting-dashboards-plugin

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-anomaly-detection-dashboards-plugin

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-config

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-maps

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-notifications

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-observability

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-query-workbench

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-reporting

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-search-relevance

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-visualizations

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-index-management-dashboards-plugin

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-ml-commons-dashboards

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-security-analytics-dashboards-plugin

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-fips-security-dashboards-plugin

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-index-management-dashboards-plugin

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-ml-commons-dashboards

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-security-analytics-dashboards-plugin

    < 2.15.0-r0

  • chainguardopensearch-dashboards-2-security-dashboards-plugin

    < 2.15.0-r0

  • chainguardpnpm-stage0

    < 8.7.4-r6

  • chainguardpy3.10-jupyterlab

    < 4.6.1-r1

  • chainguardpy3.11-jupyterlab

    < 4.6.1-r1

  • chainguardpy3.12-jupyterlab

    < 4.6.1-r1

  • chainguardpy3.13-jupyterlab

    < 4.6.1-r1

  • chainguardsqlpad

    < 7.4.1-r3

  • chainguardtensorflow-cpu-jupyter

    < 2.21.0-r8

  • chainguardtensorflow-gpu-jupyter

    all

  • wolfijupyter-base-notebook

    all

  • wolfilerna

    < 8.1.3-r0

  • wolfinpm

    < 10.5.1-r0

  • wolfipnpm-stage0

    < 8.7.4-r6

  • wolfipy3.10-jupyterlab

    < 4.6.1-r1

  • wolfipy3.11-jupyterlab

    < 4.6.1-r1

  • wolfipy3.12-jupyterlab

    < 4.6.1-r1

  • wolfipy3.13-jupyterlab

    < 4.6.1-r1

  • wolfisqlpad

    < 7.4.1-r3

Showing first 50 affected entries in server-rendered view.

References (8)