Link following in tar-fs - CVE-2024-12905
Published: March 31, 2025
Vulnerability identifier: #VU106282
CSH Severity: High
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-12905
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insecure link following in index.js. A remote attacker can supply a specially crafted file to the application and overwrite arbitrary files on the system.
Affected software
tar-fs
IBM Concert Software
Confluence Data Center
IBM Cloud Pak for Business Automation
Red Hat OpenShift Dev Spaces
Rapid Infrastructure Automation
Security QRadar EDR
Business Automation Insights
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Fedora
Ubuntu
Confluence Server
Event Streams
IBM QRadar Data Synchronization App
yarnpkg
node-tar-fs (Ubuntu package)
IBM Concert Software
Confluence Data Center
IBM Cloud Pak for Business Automation
Red Hat OpenShift Dev Spaces
Rapid Infrastructure Automation
Security QRadar EDR
Business Automation Insights
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Fedora
Ubuntu
Confluence Server
Event Streams
IBM QRadar Data Synchronization App
yarnpkg
node-tar-fs (Ubuntu package)
How to mitigate CVE-2024-12905
Install updates from vendor's website.
tar-fs - addressed in versions 1.16.4, 2.1.2, 3.0.8
IBM Concert Software - update to 2.0.0
Rapid Infrastructure Automation - update to 1.1.5.3
Security QRadar EDR - update to 3.12.18
Confluence Data Center - addressed in versions 8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2
Confluence Server - addressed in versions 8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2
Event Streams - update to 11.8.1
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
yarnpkg - addressed in versions 1.22.22-7.el8, 1.22.22-7.el9, 1.22.22-7.fc40, 1.22.22-7.fc41, 1.22.22-7.fc42
node-tar-fs (Ubuntu package) - addressed in versions 2.1.1-6ubuntu0.22.04.1~esm1, 2.1.1-6ubuntu0.24.04.1~esm1, 3.0.9+~cs2.0.4-1+deb13u1build0.25.10.1
IBM QRadar Data Synchronization App - update to 3.3.0
Red Hat OpenShift Dev Spaces - addressed in versions 3.20.0, 3.21.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.2.1
IBM Concert Software - update to 2.0.0
Rapid Infrastructure Automation - update to 1.1.5.3
Security QRadar EDR - update to 3.12.18
Confluence Data Center - addressed in versions 8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2
Confluence Server - addressed in versions 8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2
Event Streams - update to 11.8.1
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
yarnpkg - addressed in versions 1.22.22-7.el8, 1.22.22-7.el9, 1.22.22-7.fc40, 1.22.22-7.fc41, 1.22.22-7.fc42
node-tar-fs (Ubuntu package) - addressed in versions 2.1.1-6ubuntu0.22.04.1~esm1, 2.1.1-6ubuntu0.24.04.1~esm1, 3.0.9+~cs2.0.4-1+deb13u1build0.25.10.1
IBM QRadar Data Synchronization App - update to 3.3.0
Red Hat OpenShift Dev Spaces - addressed in versions 3.20.0, 3.21.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.2.1
External References
Related Security Bulletins
- Insecure link following in tar-fs package for Node.js
- Fedora EPEL 9 update for yarnpkg
- Fedora 41 update for yarnpkg
- Fedora 40 update for yarnpkg
- Fedora 42 update for yarnpkg
- Fedora EPEL 8 update for yarnpkg
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.20
- Multiple vulnerabilities in IBM Rapid Infrastructure Automation
- Multiple vulnerabilities in IBM Security QRadar EDR
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in IBM Concert Software
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component update for tar-fs package
- Multiple vulnerabilities in IBM Business Automation Insights
- Confluence Data Center and Server update for tar-fs
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM QRadar Data Synchronization App
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.21
- Ubuntu update for node-tar-fs