Описание
Path Traversal in decompress
Versions of decompress prior to 4.2.1 are vulnerable to Arbitrary File Write. The package fails to prevent extraction of files with relative paths, allowing attackers to write to any folder in the system by including filenames containing../.
Recommendation
Upgrade to version 4.2.1 or later.
Пакеты
Наименование
decompress
npm
Затронутые версииВерсия исправления
< 4.2.1
4.2.1
Связанные уязвимости
CVSS3: 9.8
nvd
почти 6 лет назад
The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal.