CVE-2021-21272 Details
Description
ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI for initial testing and a Go Module. In ORAS from version 0.4.0 and before version 0.9.0, there is a "zip-slip" vulnerability. The directory support feature allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs `oras pull`. Users of the affected versions are impacted if they are `oras` CLI users who runs `oras pull`, or if they are Go programs, which invoke `github.com/deislabs/oras/pkg/content.FileStore`. The problem has been fixed in version 0.9.0. For `oras` CLI users, there is no workarounds other than pulling from a trusted artifact provider. For `oras` package users, the workaround is to not use `github.com/deislabs/oras/pkg/content.FileStore`, and use other content stores instead, or pull from a trusted artifact provider.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/deislabs/oras/commit/96cd90423303f1bb42bd043cb4c36085e6e91e8e | CVE | Patch |
| https://github.com/deislabs/oras/releases/tag/v0.9.0 | CVE | Release Notes |
| https://github.com/deislabs/oras/security/advisories/GHSA-g5v4-5x39-vwhx | CVE | PatchVendor Advisory |
| https://pkg.go.dev/github.com/deislabs/oras/pkg/oras | CVE | Third Party Advisory |
| https://github.com/deislabs/oras/commit/96cd90423303f1bb42bd043cb4c36085e6e91e8e | [email protected] | Patch |
| https://github.com/deislabs/oras/releases/tag/v0.9.0 | [email protected] | Release Notes |
| https://github.com/deislabs/oras/security/advisories/GHSA-g5v4-5x39-vwhx | [email protected] | PatchVendor Advisory |
| https://pkg.go.dev/github.com/deislabs/oras/pkg/oras | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| deislabs oras | >= 0.4.0, < 0.9.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 21, 2024 | Reanalysis | [email protected] |
| Oct 25, 2022 | Reanalysis | [email protected] |
| Feb 2, 2021 | Initial Analysis | [email protected] |
| Jan 26, 2021 | CVE Modified | [email protected] |