Логотип exploitDog
bind:CVE-2021-37701
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-37701

Количество 16

Количество 16

ubuntu логотип

CVE-2021-37701

почти 4 года назад

The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary stat calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory, where the symlink and directory names in the archive entry used backslashes as a path separator on posix systems. The cache checking logic used both `\` and `/` characters as path separators, however `\` is a valid filename character on posix systems. By first creating a directory, and then replacing that directory with a symlink, it was thus pos...

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2021-37701

почти 4 года назад

The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary stat calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory, where the symlink and directory names in the archive entry used backslashes as a path separator on posix systems. The cache checking logic used both `\` and `/` characters as path separators, however `\` is a valid filename character on posix systems. By first creating a directory, and then replacing that directory with a symlink, it was thus pos...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2021-37701

почти 4 года назад

The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary stat calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory, where the symlink and directory names in the archive entry used backslashes as a path separator on posix systems. The cache checking logic used both `\` and `/` characters as path separators, however `\` is a valid filename character on posix systems. By first creating a directory, and then replacing that directory with a symlink, it was thus possib

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2021-37701

почти 4 года назад

The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, an ...

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-9r2w-394v-53qc

почти 4 года назад

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

CVSS3: 8.2
EPSS: Низкий
fstec логотип

BDU:2022-02880

почти 4 года назад

Уязвимость модуля Node.js для обработки tar архивов Node-tar, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю загрузить произвольные файлы и выполнить произвольный код

CVSS3: 8.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:3964-1

больше 3 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:3940-1

больше 3 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1574-1

больше 3 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1552-1

больше 3 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3964-1

больше 3 лет назад

Security update for nodejs14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3940-1

больше 3 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3886-1

больше 3 лет назад

Security update for nodejs14

EPSS: Низкий
rocky логотип

RLSA-2022:0350

больше 3 лет назад

Moderate: nodejs:14 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-0350

больше 3 лет назад

ELSA-2022-0350: nodejs:14 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0101-1

больше 3 лет назад

Security update for nodejs12

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-37701

The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary stat calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory, where the symlink and directory names in the archive entry used backslashes as a path separator on posix systems. The cache checking logic used both `\` and `/` characters as path separators, however `\` is a valid filename character on posix systems. By first creating a directory, and then replacing that directory with a symlink, it was thus pos...

CVSS3: 8.2
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2021-37701

The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary stat calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory, where the symlink and directory names in the archive entry used backslashes as a path separator on posix systems. The cache checking logic used both `\` and `/` characters as path separators, however `\` is a valid filename character on posix systems. By first creating a directory, and then replacing that directory with a symlink, it was thus pos...

CVSS3: 8.1
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-37701

The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary stat calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory, where the symlink and directory names in the archive entry used backslashes as a path separator on posix systems. The cache checking logic used both `\` and `/` characters as path separators, however `\` is a valid filename character on posix systems. By first creating a directory, and then replacing that directory with a symlink, it was thus possib

CVSS3: 8.2
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-37701

The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, an ...

CVSS3: 8.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-9r2w-394v-53qc

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

CVSS3: 8.2
0%
Низкий
почти 4 года назад
fstec логотип
BDU:2022-02880

Уязвимость модуля Node.js для обработки tar архивов Node-tar, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю загрузить произвольные файлы и выполнить произвольный код

CVSS3: 8.6
0%
Низкий
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:3964-1

Security update for nodejs14

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:3940-1

Security update for nodejs12

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1574-1

Security update for nodejs12

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1552-1

Security update for nodejs14

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:3964-1

Security update for nodejs14

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:3940-1

Security update for nodejs12

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:3886-1

Security update for nodejs14

больше 3 лет назад
rocky логотип
RLSA-2022:0350

Moderate: nodejs:14 security, bug fix, and enhancement update

больше 3 лет назад
oracle-oval логотип
ELSA-2022-0350

ELSA-2022-0350: nodejs:14 security, bug fix, and enhancement update (MODERATE)

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0101-1

Security update for nodejs12

больше 3 лет назад

Уязвимостей на страницу