OSV 1.4.0 · github-reviewed · 修改于 2026-08-21 01:26
发布时间
2026-08-21 01:26
GitHub 审查时间
2026-08-21 01:26
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/08/GHSA-j2g6-362q-6qc6/GHSA-j2g6-362q-6qc6.json
What kind of vulnerability is it? Who is impacted? If the attacker compromises the backup's object storage backend and uploads a malicious backup tarball including file names like the following:
It's possible that extracting files from the tarball during restore can overwrite sensitive files in the Velero pod filesystem.
Has the problem been patched? What versions should users upgrade to?
By far, there is no patch yet. We are working on the main branch, then cherry-pick to the release-1.18 for v1.18.1 patch.
Is there a way for users to fix or remediate the vulnerability without upgrading?
There is no workaround, but the good news is that keeping your OSS safe will prevent the vulnerability.