Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-20834

Опубликовано: 30 апр. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 6.4
EPSS Низкий

Описание

A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:isaacs:tar:*:*:*:*:*:*:*:*
Версия до 2.2.2 (исключая)
cpe:2.3:a:isaacs:tar:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 4.4.2 (исключая)

EPSS

Процентиль: 73%
0.00762
Низкий

7.5 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).

CVSS3: 8.8
redhat
почти 8 лет назад

A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).

CVSS3: 7.5
debian
почти 7 лет назад

A vulnerability was found in node-tar before version 4.4.2 (excluding ...

CVSS3: 7.5
github
почти 7 лет назад

Arbitrary File Overwrite in tar

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость модуля node-tar библиотеки Node.js, позволяющая нарушителю заменить существующее содержимое файла

EPSS

Процентиль: 73%
0.00762
Низкий

7.5 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-59