Количество 20
Количество 20
GHSA-3jfq-g458-7qm9
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization
CVE-2021-32804
The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file paths by turning absolute paths into relative paths when the `preservePaths` flag is not set to `true`. This is achieved by stripping the absolute path root from any absolute file paths contained in a tar file. For example `/home/user/.bashrc` would turn into `home/user/.bashrc`. This logic was insufficient when file paths contained repeated path roots such as `////home/user/.bashrc`. `node-tar` would only strip a single path root from such paths. When given an absolute file path with repeating path roots, the resulting path (e.g. `///home/user/.bashrc`) would still resolve to an absolute path, thus allowing arbitrary file creation and overwrite. This issue was addressed in releases 3.2.2, 4.4.14, 5.0.6 and 6.1.1. Users may work around this vulner...
CVE-2021-32804
The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file paths by turning absolute paths into relative paths when the `preservePaths` flag is not set to `true`. This is achieved by stripping the absolute path root from any absolute file paths contained in a tar file. For example `/home/user/.bashrc` would turn into `home/user/.bashrc`. This logic was insufficient when file paths contained repeated path roots such as `////home/user/.bashrc`. `node-tar` would only strip a single path root from such paths. When given an absolute file path with repeating path roots, the resulting path (e.g. `///home/user/.bashrc`) would still resolve to an absolute path, thus allowing arbitrary file creation and overwrite. This issue was addressed in releases 3.2.2, 4.4.14, 5.0.6 and 6.1.1. Users may work around this vulner...
CVE-2021-32804
The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file paths by turning absolute paths into relative paths when the `preservePaths` flag is not set to `true`. This is achieved by stripping the absolute path root from any absolute file paths contained in a tar file. For example `/home/user/.bashrc` would turn into `home/user/.bashrc`. This logic was insufficient when file paths contained repeated path roots such as `////home/user/.bashrc`. `node-tar` would only strip a single path root from such paths. When given an absolute file path with repeating path roots, the resulting path (e.g. `///home/user/.bashrc`) would still resolve to an absolute path, thus allowing arbitrary file creation and overwrite. This issue was addressed in releases 3.2.2, 4.4.14, 5.0.6 and 6.1.1. Users may work around this vulnerabi
CVE-2021-32804
The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4 ...
BDU:2022-00201
Уязвимость метода модуля Node.js для обработки tar архивов Node-tar, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании
openSUSE-SU-2022:0715-1
Security update for nodejs14
openSUSE-SU-2022:0704-1
Security update for nodejs8
openSUSE-SU-2022:0657-1
Security update for nodejs12
SUSE-SU-2022:0715-1
Security update for nodejs14
SUSE-SU-2022:0704-1
Security update for nodejs8
SUSE-SU-2022:0657-1
Security update for nodejs12
SUSE-SU-2022:0569-1
Security update for nodejs14
SUSE-SU-2022:0563-1
Security update for nodejs8
SUSE-SU-2022:0531-1
Security update for nodejs12
SUSE-SU-2022:0570-1
Security update for nodejs10
RLSA-2021:3623
Important: nodejs:12 security and bug fix update
ELSA-2021-3666
ELSA-2021-3666: nodejs:14 security and bug fix update (IMPORTANT)
ELSA-2021-3623
ELSA-2021-3623: nodejs:12 security and bug fix update (IMPORTANT)
SUSE-SU-2022:1717-1
Security update for nodejs10
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3jfq-g458-7qm9 Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization | CVSS3: 8.2 | 86% Высокий | больше 4 лет назад | |
CVE-2021-32804 The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file paths by turning absolute paths into relative paths when the `preservePaths` flag is not set to `true`. This is achieved by stripping the absolute path root from any absolute file paths contained in a tar file. For example `/home/user/.bashrc` would turn into `home/user/.bashrc`. This logic was insufficient when file paths contained repeated path roots such as `////home/user/.bashrc`. `node-tar` would only strip a single path root from such paths. When given an absolute file path with repeating path roots, the resulting path (e.g. `///home/user/.bashrc`) would still resolve to an absolute path, thus allowing arbitrary file creation and overwrite. This issue was addressed in releases 3.2.2, 4.4.14, 5.0.6 and 6.1.1. Users may work around this vulner... | CVSS3: 8.2 | 86% Высокий | больше 4 лет назад | |
CVE-2021-32804 The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file paths by turning absolute paths into relative paths when the `preservePaths` flag is not set to `true`. This is achieved by stripping the absolute path root from any absolute file paths contained in a tar file. For example `/home/user/.bashrc` would turn into `home/user/.bashrc`. This logic was insufficient when file paths contained repeated path roots such as `////home/user/.bashrc`. `node-tar` would only strip a single path root from such paths. When given an absolute file path with repeating path roots, the resulting path (e.g. `///home/user/.bashrc`) would still resolve to an absolute path, thus allowing arbitrary file creation and overwrite. This issue was addressed in releases 3.2.2, 4.4.14, 5.0.6 and 6.1.1. Users may work around this vulner... | CVSS3: 8.1 | 86% Высокий | больше 4 лет назад | |
CVE-2021-32804 The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file paths by turning absolute paths into relative paths when the `preservePaths` flag is not set to `true`. This is achieved by stripping the absolute path root from any absolute file paths contained in a tar file. For example `/home/user/.bashrc` would turn into `home/user/.bashrc`. This logic was insufficient when file paths contained repeated path roots such as `////home/user/.bashrc`. `node-tar` would only strip a single path root from such paths. When given an absolute file path with repeating path roots, the resulting path (e.g. `///home/user/.bashrc`) would still resolve to an absolute path, thus allowing arbitrary file creation and overwrite. This issue was addressed in releases 3.2.2, 4.4.14, 5.0.6 and 6.1.1. Users may work around this vulnerabi | CVSS3: 8.2 | 86% Высокий | больше 4 лет назад | |
CVE-2021-32804 The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4 ... | CVSS3: 8.2 | 86% Высокий | больше 4 лет назад | |
BDU:2022-00201 Уязвимость метода модуля Node.js для обработки tar архивов Node-tar, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании | CVSS3: 8.1 | 86% Высокий | больше 4 лет назад | |
openSUSE-SU-2022:0715-1 Security update for nodejs14 | больше 3 лет назад | |||
openSUSE-SU-2022:0704-1 Security update for nodejs8 | больше 3 лет назад | |||
openSUSE-SU-2022:0657-1 Security update for nodejs12 | больше 3 лет назад | |||
SUSE-SU-2022:0715-1 Security update for nodejs14 | больше 3 лет назад | |||
SUSE-SU-2022:0704-1 Security update for nodejs8 | больше 3 лет назад | |||
SUSE-SU-2022:0657-1 Security update for nodejs12 | больше 3 лет назад | |||
SUSE-SU-2022:0569-1 Security update for nodejs14 | больше 3 лет назад | |||
SUSE-SU-2022:0563-1 Security update for nodejs8 | больше 3 лет назад | |||
SUSE-SU-2022:0531-1 Security update for nodejs12 | больше 3 лет назад | |||
SUSE-SU-2022:0570-1 Security update for nodejs10 | больше 3 лет назад | |||
RLSA-2021:3623 Important: nodejs:12 security and bug fix update | около 4 лет назад | |||
ELSA-2021-3666 ELSA-2021-3666: nodejs:14 security and bug fix update (IMPORTANT) | около 4 лет назад | |||
ELSA-2021-3623 ELSA-2021-3623: nodejs:12 security and bug fix update (IMPORTANT) | около 4 лет назад | |||
SUSE-SU-2022:1717-1 Security update for nodejs10 | больше 3 лет назад |
Уязвимостей на страницу