Link following in tar-fs - CVE-2024-12905

 

Link following in tar-fs - CVE-2024-12905

Published: March 31, 2025


Vulnerability identifier: #VU106282
CSH Severity: High
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-12905
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insecure link following in index.js. A remote attacker can supply a specially crafted file to the application and overwrite arbitrary files on the system.


Affected software

tar-fs
IBM Concert Software
Confluence Data Center
IBM Cloud Pak for Business Automation
Red Hat OpenShift Dev Spaces
Rapid Infrastructure Automation
Security QRadar EDR
Business Automation Insights
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Fedora
Ubuntu
Confluence Server
Event Streams
IBM QRadar Data Synchronization App
yarnpkg
node-tar-fs (Ubuntu package)

How to mitigate CVE-2024-12905

Install updates from vendor's website.

tar-fs - addressed in versions 1.16.4, 2.1.2, 3.0.8
IBM Concert Software - update to 2.0.0
Rapid Infrastructure Automation - update to 1.1.5.3
Security QRadar EDR - update to 3.12.18
Confluence Data Center - addressed in versions 8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2
Confluence Server - addressed in versions 8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2
Event Streams - update to 11.8.1
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
yarnpkg - addressed in versions 1.22.22-7.el8, 1.22.22-7.el9, 1.22.22-7.fc40, 1.22.22-7.fc41, 1.22.22-7.fc42
node-tar-fs (Ubuntu package) - addressed in versions 2.1.1-6ubuntu0.22.04.1~esm1, 2.1.1-6ubuntu0.24.04.1~esm1, 3.0.9+~cs2.0.4-1+deb13u1build0.25.10.1
IBM QRadar Data Synchronization App - update to 3.3.0
Red Hat OpenShift Dev Spaces - addressed in versions 3.20.0, 3.21.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.2.1

External References

Related Security Bulletins