SCA: security update for github.com/karmada-io/karmada (GHSA-cwrh-575j-8vr3)

medium Tenable Self-Hosted Container Security Plugin ID 414149

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Karmada is a Kubernetes management system that allows users to run cloud-native applications across
multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karmadactl and karmada-operator,
it is possible to supply a filesystem path, or an HTTP(s) URL to retrieve the custom resource
definitions(CRDs) needed by Karmada. The CRDs are downloaded as a gzipped tarfile and are vulnerable to a
TarSlip vulnerability. An attacker able to supply a malicious CRD file into a Karmada initialization could
write arbitrary files in arbitrary paths of the filesystem. From Karmada version 1.12.0, when processing
custom CRDs files, CRDs archive verification is utilized to enhance file system robustness. A workaround
is available. Someone who needs to set flag `--crd` to customize the CRD files required for Karmada
initialization when using `karmadactl init` to set up Karmada can manually inspect the CRD files to check
whether they contain sequences such as `../` that would alter file paths, to determine if they potentially
include malicious files. When using karmada-operator to set up Karmada, one must upgrade one's karmada-
operator to one of the fixed versions. (CVE-2024-56514)

See Also

https://github.com/advisories/GHSA-cwrh-575j-8vr3

Plugin Details

Severity: Medium

ID: 414149

Version: Revision 1.17

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.49

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-56514

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 5.3

Threat Score: 1.3

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/3/2025

Vulnerability Publication Date: 1/3/2025

Reference Information

CVE: CVE-2024-56514

cwe: CWE-22