Описание
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
node-tar | fixed | 2.2.1-1 | package |
Примечания
libv8 is not covered by security support
EPSS
Процентиль: 58%
0.00365
Низкий
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 8 лет назад
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.
redhat
около 10 лет назад
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.
CVSS3: 7.5
nvd
больше 8 лет назад
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.
EPSS
Процентиль: 58%
0.00365
Низкий