CVE-2020-12265 – decompress-tar
Package
Manager: npm
Name: decompress-tar
Vulnerable Version: >=0 <=4.1.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS: N/A pctlN/A
Details
Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip). It is possible to bypass the security measures provided by decompress and conduct ZIP path traversal through symlinks.
Metadata
Created:
Modified:
Source: MANUAL
CWE IDs: ["CWE-29"]
Alternative ID: N/A
Finding: F063
Auto approve: 1