PT-2026-103278 · Red Hat · Assisted Installer For Red Hat Openshift Container Platform+2
CVE-2026-101295
·
Published
2026-09-30
·
Updated
2026-09-30
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
oc-mirror (affected versions not specified)
Red Hat Assisted Installer for OpenShift Container Platform (affected versions not specified)
OpenShift Container Platform (affected versions not specified)
Description
A path traversal and arbitrary file write issue exists during the operator catalog image extraction process. When mirroring operator catalogs using the legacy v1 path via the
--v1 flag or the OCI feature path via the --use-oci-feature flag, the software extracts tar entries from catalog image layers without validating that the file paths resolve within the intended destination directory. Path traversal is a technique used to access files and directories that are stored outside the web root folder by manipulating variables such as file paths.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openshift Container Platform
Assisted Installer For Red Hat Openshift Container Platform
Oc-Mirror