Логотип exploitDog
bind:"GHSA-r628-mhmh-qjhw" OR bind:"CVE-2021-32803"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-r628-mhmh-qjhw" OR bind:"CVE-2021-32803"

Количество 20

Количество 20

github логотип

GHSA-r628-mhmh-qjhw

почти 4 года назад

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2021-32803

почти 4 года назад

The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary `stat` calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory. This order of operations resulted in the directory being created and added to the `node-tar` directory cache. When a directory is present in the directory cache, subsequent calls to mkdir for that directory are skipped. However, this is also where `node-tar` checks for symlinks occur. By first creating a directory, and then repl...

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2021-32803

почти 4 года назад

The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary `stat` calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory. This order of operations resulted in the directory being created and added to the `node-tar` directory cache. When a directory is present in the directory cache, subsequent calls to mkdir for that directory are skipped. However, this is also where `node-tar` checks for symlinks occur. By first creating a directory, and then repl...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2021-32803

почти 4 года назад

The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary `stat` calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory. This order of operations resulted in the directory being created and added to the `node-tar` directory cache. When a directory is present in the directory cache, subsequent calls to mkdir for that directory are skipped. However, this is also where `node-tar` checks for symlinks occur. By first creating a directory, and then replaci

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2021-32803

почти 4 года назад

The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4 ...

CVSS3: 8.2
EPSS: Низкий
fstec логотип

BDU:2022-00226

почти 4 года назад

Уязвимость модуля Node.js для обработки tar архивов Node-tar, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании

CVSS3: 8.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0715-1

больше 3 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0704-1

больше 3 лет назад

Security update for nodejs8

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0657-1

больше 3 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0715-1

больше 3 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0704-1

больше 3 лет назад

Security update for nodejs8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0657-1

больше 3 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0569-1

больше 3 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0563-1

больше 3 лет назад

Security update for nodejs8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0531-1

больше 3 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0570-1

больше 3 лет назад

Security update for nodejs10

EPSS: Низкий
rocky логотип

RLSA-2021:3623

почти 4 года назад

Important: nodejs:12 security and bug fix update

EPSS: Низкий
oracle-oval логотип

ELSA-2021-3666

больше 3 лет назад

ELSA-2021-3666: nodejs:14 security and bug fix update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-3623

больше 3 лет назад

ELSA-2021-3623: nodejs:12 security and bug fix update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1717-1

около 3 лет назад

Security update for nodejs10

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-r628-mhmh-qjhw

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning

CVSS3: 8.2
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2021-32803

The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary `stat` calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory. This order of operations resulted in the directory being created and added to the `node-tar` directory cache. When a directory is present in the directory cache, subsequent calls to mkdir for that directory are skipped. However, this is also where `node-tar` checks for symlinks occur. By first creating a directory, and then repl...

CVSS3: 8.2
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2021-32803

The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary `stat` calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory. This order of operations resulted in the directory being created and added to the `node-tar` directory cache. When a directory is present in the directory cache, subsequent calls to mkdir for that directory are skipped. However, this is also where `node-tar` checks for symlinks occur. By first creating a directory, and then repl...

CVSS3: 8.1
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-32803

The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary `stat` calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory. This order of operations resulted in the directory being created and added to the `node-tar` directory cache. When a directory is present in the directory cache, subsequent calls to mkdir for that directory are skipped. However, this is also where `node-tar` checks for symlinks occur. By first creating a directory, and then replaci

CVSS3: 8.2
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-32803

The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4 ...

CVSS3: 8.2
0%
Низкий
почти 4 года назад
fstec логотип
BDU:2022-00226

Уязвимость модуля Node.js для обработки tar архивов Node-tar, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании

CVSS3: 8.1
0%
Низкий
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2022:0715-1

Security update for nodejs14

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0704-1

Security update for nodejs8

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0657-1

Security update for nodejs12

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0715-1

Security update for nodejs14

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0704-1

Security update for nodejs8

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0657-1

Security update for nodejs12

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0569-1

Security update for nodejs14

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0563-1

Security update for nodejs8

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0531-1

Security update for nodejs12

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0570-1

Security update for nodejs10

больше 3 лет назад
rocky логотип
RLSA-2021:3623

Important: nodejs:12 security and bug fix update

почти 4 года назад
oracle-oval логотип
ELSA-2021-3666

ELSA-2021-3666: nodejs:14 security and bug fix update (IMPORTANT)

больше 3 лет назад
oracle-oval логотип
ELSA-2021-3623

ELSA-2021-3623: nodejs:12 security and bug fix update (IMPORTANT)

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1717-1

Security update for nodejs10

около 3 лет назад

Уязвимостей на страницу