GHSA-g5v4-5x39-vwhx

    Dashboard / Vulnerabilities / GHSA-g5v4-5x39-vwhx

    GHSA-g5v4-5x39-vwhx

    Published: 15 Feb 2022Last Modified: 8 Jul 2026

    Summary: Zip slip directory exploit in github.com/deislabs/oras

    Details: ### Impact The directory support (#55) allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs `oras pull`. Precisely, the following users of the affected versions are impacted - `oras` CLI users who runs `oras pull`. - Go programs, which invokes `github.com/deislabs/oras/pkg/content.FileStore`. ### Patches The problem has been patched by the PR linked with this advisory. Users should upgrade their `oras` CLI and packages to `0.9.0`. ### Workarounds For `oras` CLI users, there is no workarounds other than pulling from a trusted artifact provider. For `oras` package users, the workaround is to not use `github.com/deislabs/oras/pkg/content.FileStore`, and use other content stores instead, or pull from a trusted artifact provider. ### References - [Zip Slip](https://github.com/snyk/zip-slip-vulnerability) ### For more information If you have any questions or comments about this advisory: * Open an issue on the [GitHub repo](https://github.com/deislabs/oras) * Email the [list of maintainers](https://github.com/deislabs/oras/blob/main/MAINTAINERS)

    Affected packages

    Package

    Name: github.com/deislabs/oras

    Purl: pkg:golang/github.com/deislabs/oras

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.9.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-g5v4-5x39-vwhx | CVE-DB