Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-20834

Опубликовано: 30 апр. 2018
Источник: redhat
CVSS3: 8.8

Описание

A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).

A flaw was found in nodejs-tar in versions prior to 4.4.2. An arbitrary file overwrite can occur when extracting tarballs containing a hard-link to a file that already exists in the system. Further, a file that matches the hard-link may overwrite the system's files with the contents of the extracted file. The highest threat from the vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

In Red Hat OpenShift Logging the openshift-logging/kibana6-rhel8 container bundles many nodejs packages as a build time dependencies, including the tar package. The vulnerable nodejs tar package is not used in a way that makes this vulnerability exploitable, hence the impact to OpenShift Logging by this vulnerability is Low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Red Hat Enterprise Linux 8nodejs:10/nodejsNot affected
Red Hat Mobile Application Platform 4nodejs-tarNot affected
Red Hat OpenShift Container Platform 3.10kibanaNot affected
Red Hat OpenShift Container Platform 3.11kibanaNot affected
Red Hat OpenShift Container Platform 3.6kibanaNot affected
Red Hat OpenShift Container Platform 3.7kibanaNot affected
Red Hat OpenShift Container Platform 3.9kibanaNot affected
Red Hat OpenShift Container Platform 4kibanaNot affected
Red Hat Software Collectionsrh-nodejs10-nodejsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=1702338nodejs-tar: Arbitrary file overwrites when extracting tarballs containing a hard-link

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).

CVSS3: 7.5
nvd
почти 7 лет назад

A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).

CVSS3: 7.5
debian
почти 7 лет назад

A vulnerability was found in node-tar before version 4.4.2 (excluding ...

CVSS3: 7.5
github
почти 7 лет назад

Arbitrary File Overwrite in tar

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость модуля node-tar библиотеки Node.js, позволяющая нарушителю заменить существующее содержимое файла

8.8 High

CVSS3