VDB

RHBA-2024%3A4924

RHBA-2024%3A4924 PUBLISHED CVSS 6.5 MEDIUM

A flaw was found in ISAACS's node-tar, where it is vulnerable to a denial of service, caused by the lack of folder count validation. The vulnerability exists due to the application not properly controlling the consumption of internal resources while parsing a tar file. By sending a specially crafted request, a remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatrhdh/rhdh-rhel9-operator@sha256:c9792288095a9b9db5e1f9ad5365985a0582f2fa097f8bc72b0ca1cdb52830a1_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9rhdh/rhdh-rhel9-operator@sha256:c9792288095a9b9db5e1f9ad5365985a0582f2fa097f8bc72b0ca1cdb52830a1_amd64, rhdh/rhdh-rhel9-operator@sha256:c9792288095a9b9db5e1f9ad5365985a0582f2fa097f8bc72b0ca1cdb52830a1_amd64
Red Hatrhdh/rhdh-hub-rhel9@sha256:6b70449451b17941dd5b1cdedb764aaab2c945b5c5b432cfc97c1e07e35b7aa2_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9rhdh/rhdh-hub-rhel9@sha256:6b70449451b17941dd5b1cdedb764aaab2c945b5c5b432cfc97c1e07e35b7aa2_amd64, *
Red Hatrhdh/rhdh-operator-bundle@sha256:da263929d3a8cbc701de44f786d8c5fe3f9768dad270a1b34d8ff08e670785f0_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9rhdh/rhdh-operator-bundle@sha256:da263929d3a8cbc701de44f786d8c5fe3f9768dad270a1b34d8ff08e670785f0_amd64, *

Timeline

  • Jul 30, 2024 CVE Published
  • Apr 30, 2026 CVE Updated
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›